Unsecured Credentials: Chat Messages T1552.008
Tactic: Credential Access
Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services that support user communication. Users may share various forms of credentials (such as usernames and passwords, API keys, or authentication tokens) on private or public corporate internal communications channels.
Events covered
1 catalog event is tagged with this technique by at least one rule.
Authoring guide
These 2 rules share fields, values, and exclusions.
Fields filtered most (5 distinct)
These fields appear most often in rule filters.
Top indicator values (8 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: macOS
Domain: Endpoint