Unsecured Credentials T1552

Tactic: Credential Access

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Events covered

26 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 277 rules share fields, values, and exclusions.

Fields filtered most (222 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType73eq 52, in 21, wildcard 2exec, open, ProcessRollup2, exec_event, io.k8s.core.v1.secrets.get
process_name53eq 24, in 18, starts_with 7, regex_match 5, is_not_null 2, ne 1, wildcard 1bash, awk, cat, osascript, .
CommandLine47contains 39, wildcard 6, regex_match 4, in 3, is_not_null 1, match 1\sysvol\, --results=verified, confluence , docker --image , ntevent
event.type44eq 41, ne 2, in 1start, access, change, deletion, process_started
Image39ends_with 19, is_not_null 9, starts_with 6, wildcard 4, eq 2, contains 1\findstr.exe, /dev/shm/, \find.exe, /.*, /boot/*
TargetFilename35wildcard 22, in 5, contains 4, ends_with 3, starts_with 3, eq 2/users/*/.electrum/*, /users/*/library/application support/*/default/local..., /users/*/library/application support/@trezor/*, *\appdata\roaming\atomic\localstorage\leveldb*, *\appdata\roaming\raven\*wallet*
host.os.type34eq 29, in 5
EventID31eq 314688, 4104, 1, 4663, 4662
data_stream.dataset30eq 30gcp.audit, aws.cloudtrail, azure.activitylogs, kubernetes.audit_logs, auditd_manager.auditd
event.outcome25eq 25success, failure
process.args24in 12, wildcard 10, eq 9, contains 5, starts_with 3, ends_with 1, regex_match 1/bin/awk, /bin/cat, /bin/head, *socat *, --output
event.category17eq 14, in 3file, process, registry, network
OriginalFileName16eq 16findstr.exe, find.exe, reg.exe, wevtutil.exe, wmic.exe
file.name11eq 9, in 1, ne 1, wildcard 1cookies.sqlite, cookies, cookies.binarycookies, cert?.db, key?.db
ServiceName10eq 10k8s.io, compute.googleapis.com

Top indicator values (2514 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
331078
event.typeeq
access
710
event.outcomeeq
success
21369
EventTypeeq
open
1952
EventTypeeq
exec
14576
ServiceNameeq
k8s.io
937
data_stream.dataseteq
gcp.audit
969
data_stream.dataseteq
aws.cloudtrail
8169
event.categoryeq
process
9142
usernamecontains
serviceaccount
924
EventIDeq
4688
8317
EventIDeq
4104
6269
EventTypein
exec
8201
EventTypein
exec_event
7149
EventTypein
executed
698
EventTypein
start
6163
OriginalFileNameeq
findstr.exe
812
file.nameeq
cookies.sqlite
711
file.nameeq
key?.db
711
file.nameeq
logins.json
711
process_idne
4
744
process_namein
bash
7202
process_namein
cat
727
process_namein
dash
7170
process_namein
fish
7163
process_namein
ksh
7163
process_namein
sh
7197
process_namein
zsh
7196
process_namestarts_with
python
771
container.idwildcard
*
626

Exclusions (760 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
usernamein
aksService
9
usernamein
masterclient
9
usernamestarts_with
system:
9
process.code_signature.trustedeq
true
8
responseStatus.codege
1
7
responseStatus.codege
400
7
responseStatus.codele
16
7
Imagewildcard
?:\windows\explorer.exe
6
Imagewildcard
?:\windows\system32\cmd.exe
5
Imagewildcard
?:\windows\system32\dllhost.exe
5
Imagewildcard
?:\windows\system32\searchprotocolhost.exe
5
namespacein
gke-system
5
namespacein
kube-node-lease
5
namespacein
kube-public
5
namespacein
kube-system
5

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 55 rules

Elastic 117 rules

Splunk 47 rules

Kusto 22 rules

YARA-L 6 rules

Panther 30 rules