Sub-technique of T1003 OS Credential Dumping.View on attack.mitre.org
Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information, including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user.
Linux stores user information such as user ID, group ID, home directory path, and login shell in /etc/passwd. A "user" on the system may belong to a person or a service. All password hashes are stored in /etc/shadow - including entries for users with no passwords and users with locked or disabled accounts.
Adversaries may attempt to read or dump the /etc/passwd and /etc/shadow files on Linux systems via command line utilities such as the cat command. Additionally, the Linux utility unshadow can be used to combine the two files in a format suited for password cracking utilities such as John the Ripper - for example, via the command /usr/bin/unshadow /etc/passwd /etc/shadow > /tmp/crack.password.db. Since the user information stored in /etc/passwd are linked to the password hashes in /etc/shadow, an adversary would need to have access to both.
Rules on DetectionCode tagged with T1003.008.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ESXi Sensitive Files Accessed | TTP | NULL | VMWare ESXi Syslog |
| Linux Auditd Possible Access To Credential Files | Anomaly | NULL | Linux Auditd Proctitle |
| Linux Possible Access To Credential Files | Anomaly | NULL | Sysmon for Linux EventID 1 |
None recorded.
| Used by | Procedure example |
|---|---|
| ToolLaZagne | LaZagne can obtain credential information from /etc/shadow using the shadow.py module. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.