insidejob
AML.T0091 Demonstrated ATT&CK T1550 ↗

Use Alternate Authentication Material

This technique has been demonstrated in research or controlled environments.

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.

AI services commonly use alternate authentication material as a primary means for users to make queries, making them vulnerable to this technique.

Sub-techniques 1