FORENSIA

ATT&CK · T1552.001 · sub-technique

Credentials In Files

Tactics: credential-access

About

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS Credential Dumping. Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller. In cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files. They may also be found as parameters to deployment commands in container logs. In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.

Platforms: Containers, IaaS, Linux, macOS, WindowsParent: T1552 Unsecured CredentialsMITRE ATT&CK ↗

Used by actors

14 known groups

Software

20 malware/tools implement this

pngdownerBlackEnergyXTunnelPupySmoke LoaderQuasarRATTrickBotjRATAgent TeslaAzorultLaZagneEmpireEmotetPoshC2PysaHildegardAADInternalsStrelaStealerShai-HuludTruffleHog

Corpus indicators tagged with this technique

561 indicators in the corpus carry T1552.001.

IndicatorTypeFamilySevSrc
cve-2026-3844cve851
cve-2025-7852cve851
cve-2025-7443cve851
cve-2025-12057cve851
cve-2021-29441cve851
cve-2026-1969cve851
cve-2026-0740cve851
cve-2025-34085cve851
cve-2016-0638cvephishing851
e8e7faa5e76dc773ffb1a7a6be36a47cc84e3ed45b928859b570332757cdb6cbsha256phishing801
ebcf977806f68af3147e0b78b55f6aedhash802
9eaa577c8ba71646928c1c34c3145536b0498f65f26060a6ba00744bcef57644sha256phishing801
340820f7f4c97e3a2477bc99acf746e13b2c92719ebf5c9947a62eef7ec0dddbsha256phishing801
cff8b04f2c8ed63d37fd393ad23652a8b818e80b03851d7c1bd5842963a03348sha256phishing801
cc19e502e4201cc974c753b96429027925224f53hash802
02048121fd0b3a51751ce7677155aa8818eba9d8ce67ea26fd1d7f43cfcdabd2hash802
d3ebce2f05fe91a8260e87fd11a6ea17c156703d081b3f91d9bbe5fd6aeedc10hashphishing802
b82936f37648518425c7d3cf9e09eaffa41d7cdb3840f6a40287e3a108880f7bsha256802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
606966a9ec33765baedf63331595d1168f2a596fhash803
d5e9288693aa745dc89368deac677e7ea1ec81e663283af30838cdae189b7a7ehashphishing802
4c0d9b802c075be79e9edb52d88f8dd72e6904f5c58267213745818470945c78hashphishing802
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
6c6cbed6aad96564ed87094785be07a1hashphishing802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
55d6238b01a177e25eb7d53c943f3abea64ec073hashphishing802
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801

Showing the top 30 by severity of 561.