Unsecured Credentials: Shell History T1552.003
Tactic: Credential Access
Adversaries may search the command history on compromised systems for insecurely stored credentials.
Events covered
3 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| ESF | exec | Process Execution |
| Linux-Auditd | Event ID 1309 | EXECVE |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 4 rules share fields, values, and exclusions.
Fields filtered most (3 distinct)
These fields appear most often in rule filters.
Top indicator values (24 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- Cisco Show Commands Input
- Suspicious History File Operations
- Suspicious History File Operations - Linux