T1552Techniquecredential-accessagent-callable

T1552Unsecured Credentials

Platforms: Windows · SaaS · IaaS · Linux · macOS · Containers · Network Devices · Office Suite · Identity Provider

ATT&CK version: v19.1

What it is

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or application-specific repositories (e.g. [Credentials in Registry](https://attack.mitre.org/techniques/T1552/002)), or other specialized files/artifacts (e.g. [Private Keys](https://attack.mitre.org/techniques/T1552/004)).(Citation: Brining MimiKatz to Unix)

ATT&CK tactics· 1

Credential Access

References

  1. https://attack.mitre.org/techniques/T1552
  2. https://labs.portcullis.co.uk/download/eu-18-Wadhwa-Brown-Where-2-worlds-collide-Bringing-Mimikatz-et-al-to-UNIX.pdf
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1552: Unsecured Credentials | SQUR Knowledge Base