← AI security in plain English

AML.T0090

MITRE ATLAS / OS Credential Dumping

Adversaries extract credentials from operating system caches, application memory, or other sources on a compromised machine, obtaining material that can be reused elsewhere.

Think of it likeGoing through the coat pockets in the cloakroom rather than picking any individual lock.

In plain English

Once on the box, an attacker pulls credentials out of memory and caches. On a shared training host that can mean the keys of every user and job that ran there.