Unsecured Credentials

T1552

Technique with 8 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Detection rules83

Rules on DetectionCode tagged with T1552 or one of its sub-techniques.

Sigma49

RuleLevelLog sourceTechnique
Application AppID Uri Configuration Changeshighazure / NULLT1552
Cisco Crypto Commandshighcisco / NULLT1552.004
Copy Passwd Or Shadow From TMP Pathhighlinux / process_creationT1552.001
Credentials In Fileshighmacos / process_creationT1552.001
Credentials In Files - Linuxhighlinux / NULLT1552.001
DPAPI Backup Keys And Certificate Export Activity IOChighwindows / file_eventT1552.004
Findstr GPP Passwordshighwindows / process_creationT1552.006
HackTool - Typical HiveNightmare SAM File Exporthighwindows / file_eventT1552.001
HackTool - WinPwn Executionhighwindows / process_creationT1552.001
HackTool - WinPwn Execution - ScriptBlockhighwindows / ps_scriptT1552.001
Linux Recon Indicatorshighlinux / process_creationT1552.001
LSASS Process Reconnaissance Via Findstr.EXEhighwindows / process_creationT1552.006
Potential Okta Password in AlternateID Fieldhighokta / NULLT1552
PowerShell Get-Process LSASShighwindows / process_creationT1552.004
Registry Export of Third-Party Credentialshighwindows / process_creationT1552.002

Splunk34

RuleTypeRiskData sourceTechnique
Add DefaultUser And Password In RegistryAnomalyNULLSysmon EventID 12, Sysmon EventID 13T1552.002
Auto Admin Logon Registry EntryTTPNULLSysmon EventID 13T1552.002
Cisco Isovalent - Access To Cloud Metadata ServiceAnomalyNULLCisco Isovalent Process ConnectT1552.005
Cisco SNMP Community String Configuration ChangesAnomalyNULLCisco IOS LogsT1552
Detect AWS Console Login by New UserHuntingNULLAWS CloudTrailT1552
Kubernetes Abuse of Secret by Unusual LocationAnomalyNULLKubernetes AuditT1552.007
Kubernetes Abuse of Secret by Unusual User AgentAnomalyNULLKubernetes AuditT1552.007
Kubernetes Abuse of Secret by Unusual User GroupAnomalyNULLKubernetes AuditT1552.007
Kubernetes Abuse of Secret by Unusual User NameAnomalyNULLKubernetes AuditT1552.007
Linux Auditd Find Private KeysTTPNULLLinux Auditd ExecveT1552.004
Linux Auditd Find Ssh Private KeysAnomalyNULLLinux Auditd ExecveT1552.004
Linux Auditd Private Keys and Certificate EnumerationAnomalyNULLLinux Auditd ExecveT1552.004
Linux Shell History Access Via Command Line UtilityAnomalyNULLSysmon for Linux EventID 1T1552.003
MCP Github Suspicious OperationHuntingNULLMCP ServerT1552.001
MCP Sensitive System File SearchHuntingNULLMCP ServerT1552.001

Sub-techniques8

IDNameExamples
T1552.001Credentials In Files41
T1552.002Credentials in Registry10
T1552.003Shell History2
T1552.004Private Keys23
T1552.005Cloud Instance Metadata API6
T1552.006Group Policy Preferences5
T1552.007Container API3
T1552.008Chat Messages1

Groups1

Software4

Campaigns1

Procedure examples6

Groups1

Used byProcedure example
GroupVolt Typhoon

Volt Typhoon has obtained credentials insecurely stored on targeted network appliances.

Software4

Used byProcedure example
MalwareAstaroth

Astaroth uses an external software known as NetPass to recover passwords.

MalwareDarkGate

DarkGate uses NirSoft tools to steal user credentials from the infected machine. NirSoft tools are executed via process hollowing in a newly-created instance of vbc.exe or regasm.exe.

ToolNPPSPY

NPPSPY captures credentials by recording them through an alternative network listener registered to the mpnotify.exe process, allowing for cleartext recording of logon information.

ToolPacu

Pacu can search for sensitive data: for example, in Code Build environment variables, EC2 user data, and Cloud Formation templates.

Campaigns1

Used byProcedure example
CampaignLeviathan Australian Intrusions

Leviathan gathered credentials hardcoded in binaries located on victim devices during Leviathan Australian Intrusions.

References1

  1. Brining MimiKatz to Unix Open source
    Tim Wadhwa-Brown. (2018, November). Where 2 worlds collide Bringing Mimikatz et al to UNIX. Retrieved October 13, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.