Unsecured Credentials T1552

Tactic: Credential Access

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Events covered

26 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 280 rules share fields, values, and exclusions.

Fields filtered most (222 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType76eq 53, in 25, wildcard 2exec, open, ProcessRollup2, exec_event, start
process_name55eq 26, in 18, starts_with 7, regex_match 5, is_not_null 2, ne 1, wildcard 1bash, awk, cat, osascript, .
CommandLine49contains 39, wildcard 8, regex_match 4, in 3, is_not_null 1, match 1\sysvol\, --results=verified, confluence , docker --image , ntevent
event.type48eq 45, ne 2, in 1start, access, change, deletion, process_started
Image39ends_with 19, is_not_null 9, starts_with 6, wildcard 4, eq 2, contains 1\findstr.exe, /dev/shm/, \find.exe, /.*, /boot/*
TargetFilename35wildcard 22, in 5, contains 4, ends_with 3, starts_with 3, eq 2/users/*/.electrum/*, /users/*/library/application support/*/default/local..., /users/*/library/application support/@trezor/*, *\appdata\roaming\atomic\localstorage\leveldb*, *\appdata\roaming\raven\*wallet*
host.os.type34eq 29, in 5
EventID31eq 314688, 4104, 1, 4663, 4662
data_stream.dataset29eq 29aws.cloudtrail, gcp.audit, azure.activitylogs, kubernetes.audit_logs, auditd_manager.auditd
event.outcome25eq 25success, failure
process.args24in 12, wildcard 10, eq 9, contains 5, starts_with 3, ends_with 1, regex_match 1/bin/awk, /bin/cat, /bin/head, *socat *, --output
event.category17eq 14, in 3file, process, registry, network
OriginalFileName16eq 16findstr.exe, find.exe, reg.exe, wevtutil.exe, wmic.exe
file.name11eq 9, in 1, ne 1, wildcard 1cookies.sqlite, cookies, cookies.binarycookies, cert?.db, key?.db
src_ip10is_not_null 10

Top indicator values (2522 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
371087
event.typeeq
access
710
event.outcomeeq
success
21375
EventTypeeq
open
1952
EventTypeeq
exec
14579
EventTypein
exec
12206
EventTypein
start
10168
EventTypein
exec_event
7150
EventTypein
executed
698
event.categoryeq
process
9141
usernamecontains
serviceaccount
924
EventIDeq
4688
8317
EventIDeq
4104
6269
OriginalFileNameeq
findstr.exe
812
ServiceNameeq
k8s.io
836
data_stream.dataseteq
aws.cloudtrail
8173
data_stream.dataseteq
gcp.audit
869
file.nameeq
cookies.sqlite
711
file.nameeq
key?.db
711
file.nameeq
logins.json
711
process_idne
4
745
process_namein
bash
7202
process_namein
cat
728
process_namein
dash
7170
process_namein
fish
7163
process_namein
ksh
7163
process_namein
sh
7197
process_namein
zsh
7196
process_namestarts_with
python
771
container.idwildcard
*
626

Exclusions (777 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
usernamein
aksService
9
usernamein
masterclient
9
usernamestarts_with
system:
9
process.code_signature.trustedeq
true
8
responseStatus.codege
1
7
responseStatus.codege
400
7
responseStatus.codele
16
7
Imagewildcard
?:\windows\explorer.exe
6
Imagewildcard
?:\windows\system32\cmd.exe
5
Imagewildcard
?:\windows\system32\dllhost.exe
5
Imagewildcard
?:\windows\system32\searchprotocolhost.exe
5
namespacein
gke-system
5
namespacein
kube-node-lease
5
namespacein
kube-public
5
namespacein
kube-system
5

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 55 rules

Elastic 120 rules

Splunk 47 rules

Kusto 22 rules

YARA-L 6 rules

Panther 30 rules