FORENSIA

ATT&CK · T1552.001 · sub-technique

Credentials In Files

Tactics: credential-access

About

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS Credential Dumping. Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller. In cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files. They may also be found as parameters to deployment commands in container logs. In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.

Platforms: Containers, IaaS, Linux, macOS, WindowsParent: T1552 Unsecured CredentialsMITRE ATT&CK ↗

Used by actors

14 known groups

Software

20 malware/tools implement this

pngdownerBlackEnergyXTunnelPupySmoke LoaderQuasarRATTrickBotjRATAgent TeslaAzorultLaZagneEmpireEmotetPoshC2PysaHildegardAADInternalsStrelaStealerShai-HuludTruffleHog

Corpus indicators tagged with this technique

561 indicators in the corpus carry T1552.001.

IndicatorTypeFamilySevSrc
cve-2026-3844cve851
cve-2025-7852cve851
cve-2025-7443cve851
cve-2025-12057cve851
cve-2021-29441cve851
cve-2026-1969cve851
cve-2026-0740cve851
cve-2025-34085cve851
cve-2016-0638cvephishing851
e8e7faa5e76dc773ffb1a7a6be36a47cc84e3ed45b928859b570332757cdb6cbsha256phishing801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
340820f7f4c97e3a2477bc99acf746e13b2c92719ebf5c9947a62eef7ec0dddbsha256phishing801
cff8b04f2c8ed63d37fd393ad23652a8b818e80b03851d7c1bd5842963a03348sha256phishing801
ebcf977806f68af3147e0b78b55f6aedhash802
02048121fd0b3a51751ce7677155aa8818eba9d8ce67ea26fd1d7f43cfcdabd2hash802
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
01e3dce00ea45829bd9f6a583004976ac63973a0hashcryptojacking801
bb10adac5b0124efedfe71102c1d5638135ec9e1cde8c8cb3353c5ed91bb9f81hashphishing802
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
606966a9ec33765baedf63331595d1168f2a596fhash803
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
cc19e502e4201cc974c753b96429027925224f53hash802
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801

Showing the top 30 by severity of 561.