Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.(Citation: TechNet Credential Theft) Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services.(Citation: Microsoft AD Accounts) Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as [OS Credential Dumping](https://attack.mitre.org/techniques/T1003) or password reuse, allowing access to privileged resources of the domain.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by User Account Management
is blocked by Multi-factor Authentication
is blocked by Privileged Account Management
is blocked by User Training
is blocked by Password Policies
is blocked by Abuse of Domain Accounts
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Account Lockout
is blocked by Identity Proofing (Identity Verification)
Impressum German English