/etc/passwd and /etc/shadow

T1003.008

Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org

About this technique

Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information, including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user.

Linux stores user information such as user ID, group ID, home directory path, and login shell in /etc/passwd. A "user" on the system may belong to a person or a service. All password hashes are stored in /etc/shadow - including entries for users with no passwords and users with locked or disabled accounts.

Adversaries may attempt to read or dump the /etc/passwd and /etc/shadow files on Linux systems via command line utilities such as the cat command. Additionally, the Linux utility unshadow can be used to combine the two files in a format suited for password cracking utilities such as John the Ripper - for example, via the command /usr/bin/unshadow /etc/passwd /etc/shadow > /tmp/crack.password.db. Since the user information stored in /etc/passwd are linked to the password hashes in /etc/shadow, an adversary would need to have access to both.

Detection rules3

Rules on DetectionCode tagged with T1003.008.

Sigma0

No Sigma rules are mapped to this technique yet.

Splunk3

RuleTypeRiskData source
ESXi Sensitive Files AccessedTTPNULLVMWare ESXi Syslog
Linux Auditd Possible Access To Credential FilesAnomalyNULLLinux Auditd Proctitle
Linux Possible Access To Credential FilesAnomalyNULLSysmon for Linux EventID 1

Groups0

None recorded.

Software1

Campaigns1

Procedure examples2

Software1

Used byProcedure example
ToolLaZagne

LaZagne can obtain credential information from /etc/shadow using the shadow.py module.

Campaigns1

Used byProcedure example
CampaignShadowRay

During ShadowRay, threat actors used `cat /etc/shadow` to steal password hashes.

References3

  1. Arctic Wolf Open source
    Julian Tuin, Stefan Hostetler, Jon Grimm, Aaron Diaz, and Trevor Daher. (2024, November 22). Arctic Wolf Observes Threat Campaign Targeting Palo Alto Networks Firewall Devices. Retrieved January 8, 2025.
  2. Linux Password and Shadow File Formats Open source
    The Linux Documentation Project. (n.d.). Linux Password and Shadow File Formats. Retrieved February 19, 2020.
  3. nixCraft - John the Ripper Open source
    Vivek Gite. (2014, September 17). Linux Password Cracking: Explain unshadow and john Commands (John the Ripper Tool). Retrieved February 19, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.