Unsecured Credentials: Shell History T1552.003

Tactic: Credential Access

Adversaries may search the command history on compromised systems for insecurely stored credentials.

Events covered

3 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 4 rules share fields, values, and exclusions.

Fields filtered most (3 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine2contains 1, in 1*.bash_history*, *.history*, *.sh_history*, .bash_history, .history
process_name1in 1cat, fmt, head
type1eq 1execve

Top indicator values (24 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommandLinecontains
.bash_history
1
CommandLinecontains
.history
1
CommandLinecontains
.sh_history
1
CommandLinecontains
.zhistory
1
CommandLinecontains
.zsh_history
1
CommandLinecontains
fish_history
1
CommandLinein
*.bash_history*
1
CommandLinein
*.history*
1
CommandLinein
*.sh_history*
1
CommandLinein
*.zhistory*
1
CommandLinein
*.zsh_history*
1
CommandLinein
*fish_history*
1
process_namein
cat
128
process_namein
fmt
13
process_namein
head
18
process_namein
less
115
process_namein
more
114
process_namein
nano
17
process_namein
sort
12
process_namein
tail
111
process_namein
uniq
12
process_namein
vi
19
process_namein
vim
116
typeeq
execve
137

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Splunk 1 rule