T1552 Unsecured Credentials
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or application-specific repositories (e.g. [Credentials in…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Russian APT Credential Theft Activitycriticalstable · windows
- Application AppID Uri Configuration Changeshightest · azure
- Cisco Crypto Commandshightest · cisco
- Copy Passwd Or Shadow From TMP Pathhightest · linux
- Credentials In Fileshightest · macos
- Credentials In Files - Linuxhightest · linux
- DPAPI Backup Keys And Certificate Export Activity IOChightest · windows
- Findstr GPP Passwordshightest · windows
- HackTool - Typical HiveNightmare SAM File Exporthightest · windows
- HackTool - WinPwn Executionhightest · windows
- HackTool - WinPwn Execution - ScriptBlockhightest · windows
- LSASS Process Reconnaissance Via Findstr.EXEhightest · windows
- Linux Recon Indicatorshightest · linux
- Potential Okta Password in AlternateID Fieldhightest · okta
- PowerShell Get-Process LSASShightest · windows
- SAM Registry Hive Handle Requesthightest · windows
- Registry Export of Third-Party Credentialshighexperimental · windows
- Script Interpreter Spawning Credential Scanner - Linuxhighexperimental · linux
- Script Interpreter Spawning Credential Scanner - Windowshighexperimental · windows
- Shai-Hulud Malicious GitHub Workflow Creationhighexperimental · linux
- Access To Potentially Sensitive Sysvol Files By Uncommon Applicationsmediumtest · windows
- Added Owner To Applicationmediumtest · azure
- Automated Collection Command Promptmediumtest · windows
- Azure Key Vault Modified or Deletedmediumtest · azure
- Azure Keyvault Key Modified or Deletedmediumtest · azure
Showing 25 of 47.
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.