LiveActive security incident?Get immediate response
MITRE ATT&CK® Detection Strategy

DET0105: Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools

MITRE ATT&CK DET0105: Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools Detection Strategy details, with…

EnterpriseDET0105Detection StrategyObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

This detection strategy is intended to help identify activity after credential material has been obtained, where an adversary may try to crack password hashes into usable passwords. For leaders, the practical issue is not only the initial credential dump; it is whether the organization can spot the follow-on work that turns stolen hashes into broader identity compromise. Because ATT&CK provides no official description or detection logic for this object, teams should treat it as a validation prompt rather than a ready-made analytic.

Executive priority

Prioritize this as an identity and incident-response readiness question: if password hashes or other credential material are accessed, can the SOC determine whether cracking-related activity followed, and can IR quickly scope which accounts may require reset, rotation, or stronger controls? This matters for business continuity because cracked credentials can extend an intrusion beyond the originally compromised host or service. It also supports audit and compliance evidence by demonstrating monitoring around credential-access behavior, specifically ATT&CK T1110.002 Password Cracking.

Technical view

The object detects T1110.002 Password Cracking under credential access. The detection strategy name points to two validation areas: suspicious access to credential/hash-containing files and use of hash analysis or password cracking-related tooling. SOC teams should confirm whether they can correlate file access events involving credential material with process execution, command-line, script, and tool telemetry. Because no platforms are specified for the detection object, use the related technique platforms as scoping guidance only: Identity Provider, Linux, macOS, and Network Devices.

Likely telemetry

  • File access events for credential, hash, configuration, or repository data that may contain password material
  • Process execution and command-line telemetry showing hash analysis or password cracking-related tools
  • Script execution and shell history where available
  • Identity provider audit logs for unusual authentication or credential-related activity following suspected hash exposure
  • Network device and configuration repository access logs where credential material may be stored

Detection direction

  • Validate that monitoring covers both sides of the behavior: access to credential/hash material and subsequent local or remote analysis activity.
  • Tune detections to reduce false positives from authorized security testing, password audit programs, incident response tooling, and administrative recovery workflows.
  • Correlate suspicious file access with new or unusual processes, large file reads, archive creation, or transfer activity when local telemetry supports it.
  • Use the relationship to T1110.002 to connect alerts to credential-access investigation playbooks, including account scoping and password reset decisions.
  • Document blind spots where file access logging, command-line capture, identity provider logs, or network device audit logs are unavailable.

Mitigation priorities

  • Limit access to files, repositories, systems, and devices that may contain password hashes or reusable credential material.
  • Strengthen privileged access controls and administrative separation so credential material exposure is less likely to become broad account compromise.
  • Ensure credential rotation and account reset procedures are ready for incidents involving hash exposure or suspected cracking.
  • Use approved password assessment activities with clear logging and change-control so defensive cracking work is distinguishable from suspicious activity.
  • Review retention and centralization of endpoint, identity provider, and network device logs needed to investigate T1110.002-related behavior.
Additional notes and limits

ATT&CK release 19.1 lists this as detection strategy DET0105, version 1.0, named “Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools.” The object has no official description and no official detection text, so the take is derived from the name, external reference, and its relationship to T1110.002 Password Cracking.

Coverage cannot be inferred from this object alone. The detection object does not specify platforms, tactics, or analytic logic, and local telemetry availability will decide whether the strategy is actionable. Do not assume malicious activity solely from cracking-tool or hash-file indicators without context, because legitimate security and recovery workflows may look similar.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools

No official description is available in the imported ATT&CK source object.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.0
Created
Modified
Raw hash
8480e0606a4502ce...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.