Unsecured Credentials: Chat Messages T1552.008

Tactic: Credential Access

Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services that support user communication. Users may share various forms of credentials (such as usernames and passwords, API keys, or authentication tokens) on private or public corporate internal communications channels.

Events covered

1 catalog event is tagged with this technique by at least one rule.

ProviderEventTitle
ESFopenFile Open

Authoring guide

These 2 rules share fields, values, and exclusions.

Fields filtered most (5 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType2eq 2open
TargetFilename2wildcard 2/users/*/library/application support/slack/cookies.sqlite, /users/*/library/application..., /users/*/library/containers/com.tinyspeck.slackmacgap/dat...
process.code_signature.exists1eq 1false
process.code_signature.trusted1eq 1false
process_name1eq 1osascript

Top indicator values (8 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventTypeeq
open
252
TargetFilenamewildcard
/users/*/library/application support/slack/cookies.sqlite
22
TargetFilenamewildcard
/users/*/library/application support/slack/storage/slack-workspaces.db
22
TargetFilenamewildcard
/users/*/library/containers/com.tinyspeck.slackmacgap/data/library/applicatio...
22
TargetFilenamewildcard
/users/*/library/containers/com.tinyspeck.slackmacgap/data/library/applicatio...
22
process.code_signature.existseq
false
1119
process.code_signature.trustedeq
false
1115
process_nameeq
osascript
146

Rules under this technique

These vendors publish rules tagged with this technique.

Platform: macOS

Domain: Endpoint

Elastic 2 rules