T1552.001 Credentials In Files
Sub-technique of T1552 Unsecured Credentials
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Potential Russian APT Credential Theft Activitycriticalstable · windows
- Copy Passwd Or Shadow From TMP Pathhightest · linux
- Credentials In Fileshightest · macos
- Credentials In Files - Linuxhightest · linux
- HackTool - Typical HiveNightmare SAM File Exporthightest · windows
- HackTool - WinPwn Executionhightest · windows
- HackTool - WinPwn Execution - ScriptBlockhightest · windows
- Linux Recon Indicatorshightest · linux
- Shai-Hulud Malicious GitHub Workflow Creationhighexperimental · linux
- Automated Collection Command Promptmediumtest · windows
- Azure Key Vault Modified or Deletedmediumtest · azure
- Azure Keyvault Key Modified or Deletedmediumtest · azure
- Azure Keyvault Secrets Modified or Deletedmediumtest · azure
- Extracting Information with PowerShellmediumtest · windows
- Hidden Flag Set On File/Directory Via Chflags - MacOSmediumtest · macos
- Potentially Suspicious JWT Token Search Via CLImediumtest · windows
- Remote File Download Via Findstr.EXEmediumtest · windows
- PUA - TruffleHog Executionmediumexperimental · windows
- PUA - TruffleHog Execution - Linuxmediumexperimental · linux
- Potential PowerShell Console History Access Attempt via History Filemediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.