Use of Known Domain Credentials
CAPEC-560 · Meta · Stable
An adversary guesses or obtains (i.e. steals or purchases) legitimate credentials (e.g. userID/password) to achieve authentication and to perform authorized actions under the guise of an authenticated user or service.
likelihood: High
severity: High