AltaySec · ATLAS 2026.07
AML.T0091

Use Alternate Authentication Material

C · Explainer (cannot be honestly simulated in-browser) AML.TA0015 · Lateral Movement

Description

Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls. AI services commonly use alternate authentication material as a primary means for users to make queries, making them vulnerable to this technique.

Honesty-tier rationale

Lateral movement presupposes a real multi-host / multi-account environment to traverse; there is nothing to enact client-side.

Sub-techniques

Source

← Back to the matrix