ATLASAML.T0090
ATLAS index
AML.T0090

OS Credential Dumping

Adversaries may extract credentials from OS caches, application memory, or other sources on a compromised system. Credentials are often in the form of a hash or clear text, and can include usernames and passwords, application tokens, or other authentication keys. Credentials can be used to perform Lateral Movement to a

Framework
MITRE ATLAS
Maturity
Demonstrated
Platforms
Enterprise
Release
2026.05

Overview

Adversaries may extract credentials from OS caches, application memory, or other sources on a compromised system. Credentials are often in the form of a hash or clear text, and can include usernames and passwords, application tokens, or other authentication keys.

Credentials can be used to perform Lateral Movement to access other AI services such as AI agents, LLMs, or AI inference APIs. Credentials could also give an adversary access to other software tools and data sources that are part of the AI DevOps lifecycle.

Sources

  1. MITRE ATLAS AML.T0090: OS Credential Dumping — MITRE