ATT&CK · T1552
Unsecured Credentials
Tactics: credential-access
About
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Platforms: Windows, SaaS, IaaS, Linux, macOS, Containers, Network Devices, Office Suite, Identity ProviderMITRE ATT&CK ↗
Used by actors
1 known groups
Software
4 malware/tools implement this
AstarothPacuDarkGateNPPSPY
Corpus indicators tagged with this technique
23 indicators in the corpus carry T1552.