ATT&CK 기법 · Credential Access
Steal Application Access Token T1528
이 기법을 다룬 REVELARE 한국어 위협 분석 3편 · Credential Access
이 기법을 다룬 분석
MITRE 공식 정의
Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS).(Citation: Auth0 - Why You Should Always Use Access Tokens to Secure APIs Sept 2019) Adversaries who steal account API tokens in c…
플랫폼: Containers, IaaS, Identity Provider, Office Suite, SaaS