> For the complete documentation index, see [llms.txt](https://windows.dfirhandbook.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://windows.dfirhandbook.com/windows-dfir-and-mittr/credential-access.md).

# Credential Access

* T1555: Credentials from Password Stores
* T1110: Brute Force
* T1558: Steal or Forge Kerberos Tickets
* T1539: Steal Web Session Cookie
* T1003: OS Credential Dumping
* T1056: Input Capture
* T1187: Forced Authentication
* T1212: Exploitation for Credential Access
* T1528: Steal Application Access Token
