T1552 — Unsecured Credentials
T1552: Unsecured Credentials
MITRE ATT&CK® Enterprise technique
| Tactics | Credential Access |
| Platforms | Windows, SaaS, IaaS, Linux, macOS, Containers, Network Devices, Office Suite, Identity Provider |
| Permissions required | — |
| Version | 1.5 |
Description
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).(Citation: Brining MimiKatz to Unix)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1552
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/