Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Credential Access

T1552.001 Credentials In Files

Sub-technique of T1552 Unsecured Credentials

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.