FORENSIA

ATT&CK · T1552

Unsecured Credentials

Tactics: credential-access

About

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network Devices, Office Suite, Identity ProviderMITRE ATT&CK ↗

Used by actors

1 known groups

Software

4 malware/tools implement this

AstarothPacuDarkGateNPPSPY

Corpus indicators tagged with this technique

23 indicators in the corpus carry T1552.

IndicatorTypeFamilySevSrc
c5aed4c063d4970a03250778da8041da9e0c83d8f22d2f1994da0ad72567ebd9sha256supply_chain801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
8e571d58794b9b44ae53c2c67bedef72c500e8adbb80aab7a5c263adcba55b1esha256supply_chain801
96357529d17c4690826d5d4c74deac51743a5388733b3f04004d898f0635ef20sha256supply_chain801
9df01d242ef46adfedf8c35cb7cc67b1d27d7dc4a1ce74ab32e984090d579886sha256supply_chain801
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
fb94b2caee2c40635448a98ba0118421e19a400e74ccff73315f8fa42351f53fsha256supply_chain801
cc97517f80f567977300450de11e9a0be53f52657525a20b1091c99fe9e45730sha256supply_chain801
3e6360f83a95540aa2176d279ca4694513afb1e5116a7ffe591c6b5bcf3b9c3csha256supply_chain801
4e7639045b4a64de60bfb6312951a5c3dffbd3fb04b84837663242ed27f09864sha256supply_chain801
54bf36910d81ab516037cb3d69d7c85190f90aa0da9e58617799c1fc738dc5a9sha256supply_chain801
268a8420b791df46380ed9ad69905207e15d8a7csha1phishing781
7f74bb6ba185978134c318bc5f91d23cmd5phishing761
http://45.207.216.55:8084/slturl751
193.8.187.42ipphishing701
upload.rightwidth.devdomainsupply_chain651
ldb.rightwidth.devdomainsupply_chain651
controller.rightwidth.devdomainsupply_chain651
file.rightwidth.devdomainsupply_chain651