Proc Filesystem

T1003.007

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc/<PID>/maps` file shows how memory is mapped within the process’s virtual address space. And `/proc/<PID>/mem`, exposed for debugging purposes, provides access to the process’s virtual address space.

When executing with root privileges, adversaries can search these memory locations for all processes on a system that contain patterns indicative of credentials. Adversaries may use regex patterns, such as grep -E "^[0-9a-f-]* r" /proc/"$pid"/maps | cut -d' ' -f 1, to look for fixed strings in memory structures or cached hashes. When running without privileged access, processes can still view their own virtual memory locations. Some services or programs may save credentials in clear text inside the process’s memory.

If running as or with the permissions of a web browser, a process can search the `/maps` & `/mem` locations for common website credential patterns (that can also be used to find adjacent memory within the same structure) in which hashes or cleartext credentials may be located.

Detection rules0

Rules on DetectionCode tagged with T1003.007.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk0

No Splunk rules are mapped to this technique yet.

Groups0

None recorded.

Software5

Campaigns0

None recorded.

Procedure examples5

Software5

Used byProcedure example
ToolLaZagne

LaZagne can use the `<PID>/maps` and `<PID>/mem` files to identify regex patterns to dump cleartext passwords from the browser's process memory.

ToolMimiPenguin

MimiPenguin can use the `<PID>/maps` and `<PID>/mem` file to search for regex patterns and dump the process memory.

MalwareMini Shai-Hulud

Mini Shai-Hulud has scraped runner process memory to extract short-lived identity tokens, which it then exchanged for per-package npm trusted-publisher tokens.

MalwarePACEMAKER

PACEMAKER has the ability to extract credentials from OS memory.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can scrape memory from the Runner.Worker process by reading `/proc/<pid>/mem` to extract secrets including plaintext tokens.

References5

  1. MimiPenguin GitHub May 2017 Open source
    Gregal, H. (2017, May 12). MimiPenguin. Retrieved December 5, 2017.
  2. Picus Labs Proc cump 2022 Open source
    Huseyin Can YUCEEL & Picus Labs. (2022, March 22). Retrieved March 31, 2023.
  3. Polop Linux PrivEsc Gitbook Open source
    Carlos Polop. (2023, March 5). Linux Privilege Escalation. Retrieved March 31, 2023.
  4. atomic-red proc file system Open source
    Atomic Red Team. (2023, November). T1003.007 - OS Credential Dumping: Proc Filesystem. Retrieved March 28, 2024.
  5. baeldung Linux proc map 2022 Open source
    baeldung. (2022, April 8). Understanding the Linux /proc/id/maps File. Retrieved March 31, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.