Esc
Credential Revocation
Definition
Deleting a set of credentials permanently to prevent them from being used to authenticate.
How it works
Management servers with enterprise policies for account management provide the ability remove permissions, accounts, or credentials. Compromised credentials should be revoked to prevent further malicious activity.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related ATT&CK Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, .
Privilege Escalation
Access Token Manipulation
Account Manipulation
Credential Access
Brute Force
OS Credential Dumping
Steal or Forge Kerberos Tickets
Steal Application Access Token
Steal Web Session Cookie
Keychain
Unsecured Credentials
Forge Web Credentials
Defense Evasion
Access Token Manipulation
Use Alternate Authentication Material
References
All
Specification
The following references were used to develop the Credential Revocation knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Revoke a previously issued verifiable credential
Reference Type: Specification Organization: Microsoft Author: Barclay Neira, Christer Ljung, Juan Camilo Ruiz, John Flores