{
  "technique_id": "T1528",
  "name": "Steal Application Access Token",
  "tactics": [
    "Credential Access"
  ],
  "platforms": [
    "Containers",
    "IaaS",
    "Identity Provider",
    "Office Suite",
    "SaaS"
  ],
  "summary": "Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on behalf of a user or service and are commonly used as a way to access resources in cloud and container-based applications and software-as-a-service (SaaS)...",
  "generated_by": "SOC Response Atlas by Basyrix"
}