Credential & Identity Access
Credential and identity access manipulates the people and workflows that govern identity, including users, helpdesk agents, approvers, administrators, mobile carriers, and access owners. The objective may be a password, authenticator action, account recovery, session, token, consent grant, delegated access, or control of a phone number used in recovery.
Credentials, sessions, tokens and access grants can turn a successful interaction into authenticated or continuing access. Identity controls may be weakened where a user, support agent, approver, or administrator is induced to disclose, reset or approve something outside the intended workflow.
A valid authentication or genuine approval does not by itself establish that the underlying request was authorised or safe. Credential and identity access can be assessed by asking:
- What credential, factor, session, token, approval, or access state is being targeted?
- Who is being influenced to create or expose that access?
- Does the action match an expected identity workflow and business need?
- What notification, review, or recovery step can detect and contain misuse?
Techniques
Section titled “Techniques”Credential & Identity Access includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.
- SE-T007.001Credential CaptureInfluencing a user to enter usernames, passwords, recovery codes, or other credentials into attacker-controlled systems.
- SE-T007.002MFA ManipulationInfluencing a user to approve, bypass, weaken, or interfere with MFA protections.
- SE-T007.003Account Recovery ManipulationExploiting account recovery, password reset, MFA reset, or identity proofing workflows.
- SE-T007.004Session & Token AccessInfluencing a user to expose, transfer, or surrender authenticated session or token access, including session cookies, device-code access, or other authenticated state.
- SE-T007.005Authentication Relay & InterceptionMediating or relaying a live authentication exchange through an attacker-controlled channel.
- SE-T007.006Shared Account & Delegated Access AbuseExploiting shared accounts, generic credentials, shared mailboxes, informal delegation, or unclear account ownership.
- SE-T007.007Access & Consent Approval ManipulationInfluencing a user or approver to authorise application consent, external sharing, delegated access, privileges, or another access grant.
- SE-T007.008SIM Swap & Phone-Number TakeoverManipulating a mobile carrier to transfer a victim's number and take control of phone-based authentication or recovery.
Behavioural Indicators
Section titled “Behavioural Indicators”Credential and identity access activity may involve one or more of the following behaviours:
Credential and authentication targeting
- directing users to login portals, consent screens, verification pages, or approval prompts
- requesting usernames, passwords, recovery codes, one-time codes, device codes, or MFA approvals
- creating urgency around account access, security, suspension, compliance, or missed messages
- delivering login, recovery, consent, or approval lures through email, SMS, chat, calendar invites, shared documents, or collaboration platforms
- using fake authentication interfaces, system notifications, support interactions, or mirrored identity workflows
MFA and approval manipulation
- sending multiple MFA push notifications in quick succession
- asking users to approve a prompt, enter a code, scan a QR code, or complete a device-code flow
- framing the approval as routine, urgent, required, or part of an IT/security process
- exploiting fatigue, cognitive load, confusion, fear, urgency, or authority pressure to gain approval
- asking users not to report unexpected prompts because the issue is “being handled”
Identity workflow and recovery behaviour
- requesting password resets, MFA resets, account unlocks, security information changes, or recovery method updates
- pressuring helpdesk, identity, HR, or managers to act quickly on account recovery or access restoration
- using stories about lost phones, urgent travel, inaccessible accounts, locked portals, or business disruption
- targeting a mobile carrier to port, transfer, or reassign a user’s number so SMS or voice one-time codes and phone-based recovery can be intercepted
- providing documents, phone numbers, email addresses, or identity proofing details that cannot be independently verified
- attempting repeated recovery through different staff, teams, or channels after delay or refusal
Access and consent behaviour
- encouraging users or administrators to grant app consent, external sharing, delegated access, mailbox access, privileged access, or elevated roles
- presenting access approval as already authorised, routine, time-sensitive, or required by a senior person
- exploiting shared accounts, generic accounts, delegated permissions, weak ownership, or unclear approval paths
- requesting approval outside the expected workflow or without a verifiable business need