Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

Alert response · Credential Access responders

Credential theft

Something tried to read, guess or forge credentials. Assume what it touched is now known to the adversary.

Assume every credential in reach is already known. Confirmation takes hours; a stolen hash or a live session is usable in minutes.

What this does not establish

  • Whether the read succeeded — a handle is an attempt, not an extraction.
  • Which accounts were exposed. That depends on sessions since last reboot.
  • Whether it is the first attempt. Credential access is usually late in a chain.
  • Whether anything left with them. Access and exfiltration are separate questions.

0 of 20 ticked

Selected step

DetectStep 1 of 20Decision

Two shapes arrive here: something read credentials on a host, or an account was taken over.

Did this start at a sign-in, not a process?

If yes: go to — Skip the host questions; the sign-in log is the evidenceOtherwise continue to “Identify the reading process and its parent”.

  • Brute force, spray and phishing leave no reading process to find.
  • Browser and vault theft arrive either way; take the path with evidence.
  • Start the timeline now: every action, who took it, when.