Umbra Wiki technique technique/T1552
Back to wiki

T1552 — Unsecured Credentials

provenance: imported · ATT&CK: T1552

T1552: Unsecured Credentials

MITRE ATT&CK® Enterprise technique

Tactics Credential Access
Platforms Windows, SaaS, IaaS, Linux, macOS, Containers, Network Devices, Office Suite, Identity Provider
Permissions required
Version 1.5

Description

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).(Citation: Brining MimiKatz to Unix)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1552
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/