Unsecured Credentials T1552
Tactic: Credential Access
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Events covered
26 catalog events are tagged with this technique by at least one rule.
Authoring guide
These 277 rules share fields, values, and exclusions.
Fields filtered most (222 distinct)
These fields appear most often in rule filters.
Top indicator values (2514 distinct)
These values appear most often in rule predicates.
Exclusions (760 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 55 rules
- Access To Potentially Sensitive Sysvol Files By Uncommon Applications
- Access To Sysvol Policies Share By Uncommon Process
- Added Owner To Application
- Application AppID Uri Configuration Changes
- Automated Collection Command Prompt
- Azure Key Vault Modified or Deleted
- Azure Keyvault Key Modified or Deleted
- Azure Keyvault Secrets Modified or Deleted
- Azure Kubernetes Admission Controller
- Certificate Exported Via PowerShell
- Certificate Exported Via PowerShell - ScriptBlock
- Cisco Collect Data
- Cisco Crypto Commands
- Cisco Show Commands Input
- Copy Passwd Or Shadow From TMP Path
- Credentials In Files
- Credentials In Files - Linux
- DPAPI Backup Keys And Certificate Export Activity IOC
- Enumeration for 3rd Party Creds From CLI
- Enumeration for Credentials in Registry
- EventLog Query Requests By Builtin Utilities
- Extracting Information with PowerShell
- Findstr GPP Passwords
- Google Cloud Kubernetes Admission Controller
- HackTool - Typical HiveNightmare SAM File Export
- HackTool - WinPwn Execution
- HackTool - WinPwn Execution - ScriptBlock
- Hidden Flag Set On File/Directory Via Chflags - MacOS
- Insensitive Subfolder Search Via Findstr.EXE
- Kubernetes Admission Controller Modification
- Kubernetes Secrets Enumeration
- Linux Recon Indicators
- LSASS Process Reconnaissance Via Findstr.EXE
- Permission Misconfiguration Reconnaissance Via Findstr.EXE
- PFX File Creation
- Potential Okta Password in AlternateID Field
- Potential Password Reconnaissance Via Findstr.EXE
- Potential PowerShell Console History Access Attempt via History File
- Potential Russian APT Credential Theft Activity
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities
- Potentially Suspicious JWT Token Search Via CLI
- PowerShell Get-Process LSASS
- Private Keys Reconnaissance Via CommandLine Tools
- PUA - TruffleHog Execution
- PUA - TruffleHog Execution - Linux
- Registry Export of Third-Party Credentials
- Remote File Download Via Findstr.EXE
- SAM Registry Hive Handle Request
- Script Interpreter Spawning Credential Scanner - Linux
- Script Interpreter Spawning Credential Scanner - Windows
- Shai-Hulud Malicious GitHub Workflow Creation
- Suspicious History File Operations
- Suspicious History File Operations - Linux
- Suspicious SYSVOL Domain Group Policy Access
- Unattend.XML File Access Attempt
Elastic 117 rules
- Access Attempt to Non Existing Cryptocurrency Wallet
- Access to a Sensitive LDAP Attribute
- Access to Browser Credentials from Suspicious Memory
- Attempted Private Key Access
- AutoLogons Access Attempt via Registry
- AWS Bedrock AgentCore Execution Role Used Outside Its Runtime
- AWS Bedrock AgentCore Runtime Prompt Containing Credentials
- AWS Bedrock AgentCore Runtime Prompt Targeting Credentials or Instance Metadata
- AWS Bedrock Model Prompt or Completion Containing Credentials
- AWS Cognito Unauthenticated Identity Pool Credentials Issued
- AWS Credentials Searched For Inside A Container
- AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization
- AWS EC2 Instance Console Login via Assumed Role
- AWS EC2 Unauthorized Admin Credential Fetch via Assumed Role
- AWS EC2 User Data Retrieval for EC2 Instance
- AWS IAM CompromisedKeyQuarantine Policy Attached to User
- AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts
- AWS IAM Long-Term Access Key First Seen from Source IP
- AWS S3 Credential File Retrieved from Bucket
- Azure AKS Secret get or list with Suspicious User Agent
- Azure Arc Cluster Credential Access by Identity from Unusual Source
- Azure Event Hub Authorization Rule Created or Updated
- Azure Service Principal Sign-In Followed by Arc Cluster Credential Access
- Azure Storage Account Key Regenerated
- Azure VM Boot Diagnostics Retrieved
- Cloud Credential Files Accessed by Osascript
- Cloud Credential Files Accessed by Process in Suspicious Directory
- Cloud Credential Search Detected via Defend for Containers
- Cloud Instance Metadata Credential Path HTTP Request
- Command Shell Activity Started via RunDLL32
- Creation or Modification of Domain Backup DPAPI private key
- Credential Access via TruffleHog Execution
- Crypto Wallet File Access by Unsigned or Untrusted Binary
- Crypto Wallet File Access via CommandLine
- Crypto Wallet or Web Browser File Access via Nodejs
- Crypto Wallet or Web Browser File Access via Osascript
- Crypto Wallet or Web Browser File Access via Python
- Crypto Wallet or Web Browser File Access via SSH
- Failed Access Attempt to Web Browser Files
- Failed Attempts to Access Sensitive Files
- First Time Python Accessed Sensitive Credential Files
- GenAI Process Accessing Sensitive Files
- GitHub Authentication Token Access via Node.js
- GKE Pod Exec Cloud Instance Metadata Access
- GKE Pod Exec Sensitive File or Credential Path Access
- GKE Rapid Secret GET Activity Against Multiple Objects
- GKE Secret Access from Node or Denied Service Account
- GKE Secret Access via Unusual User Agent
- GKE Secret get or list with Suspicious User Agent
- GKE Secrets List from Unusual Source AS Organization
- GKE Service Account Token Created via TokenRequest API
- GKE Unusual Service Account Secret Access via New User Agent
- Google Workspace Drive Encryption Key(s) Accessed from Anonymous User
- Kubeconfig File Creation or Modification
- Kubeconfig File Discovery
- Kubectl Secrets Enumeration Across All Namespaces
- Kubelet Certificate File Access Detected via Defend for Containers
- Kubernetes and Cloud Credential Path Access via Process Arguments
- Kubernetes Direct API Request via Curl or Wget
- Kubernetes Pod Exec Cloud Instance Metadata Access
- Kubernetes Pod Exec Sensitive File or Credential Path Access
- Kubernetes Rapid Secret GET Activity Against Multiple Objects
- Kubernetes Secret Access via Unusual User Agent
- Kubernetes Secret get or list from Node or Pod Service Account
- Kubernetes Secret get or list with Suspicious User Agent
- Kubernetes Secret or ConfigMap Access via Azure Arc Proxy
- Kubernetes Secrets List Across Cluster or Sensitive Namespaces
- Kubernetes Service Account Secret Access
- Kubernetes Service Account Token Created via TokenRequest API
- Microsoft IIS Connection Strings Decryption
- Microsoft IIS Service Account Password Dumped
- Multi-Cloud CLI Token and Credential Access Commands
- Potential Browser Credentials Stealer
- Potential Credential Discovery via Recursive Grep
- Potential Impersonation Attempt via Kubectl
- Potential Kerberos Attack via Bifrost
- Potential PowerShell HackTool Script by Function Names
- Potential Privilege Escalation via Linux DAC permissions
- Potential Python Stealer
- Potential Secret Scanning via Gitleaks
- PowerShell Script with Password Policy Discovery Capabilities
- Private Key Searching Activity
- Protected Storage Service Access via SMB
- Security File Access via Common Utilities
- Sensitive File Access - Cloud Credentials
- Sensitive File Access - Remote Desktop Connection Manager
- Sensitive File Access - SSH Saved Keys
- Sensitive File Access - System Admin Utilities
- Sensitive File Access - Unattended Panther
- Sensitive File Access via Perl
- Sensitive File Compression Detected via Defend for Containers
- Sensitive Files Compression
- Sensitive Files Compression Inside A Container
- Sensitive Identity File Open by Suspicious Process via Auditd
- Sensitive Keys Or Passwords Search Detected via Defend for Containers
- Sensitive Keys Or Passwords Searched For Inside A Container
- Service Account Token or Certificate Access Followed by Kubernetes API Request
- Service Account Token or Certificate Read Detected via Defend for Containers
- Slack Workspace Files Accessed by Osascript
- Slack Workspace Files Accessed by Unsigned or Untrusted Process
- SSH Keys Accessed by Osascript
- Suspicious Access to Cryptocurrency Wallet Files
- Suspicious CertUtil Commands
- Suspicious Instance Metadata Service (IMDS) API Command Line Execution
- Suspicious Instance Metadata Service (IMDS) API Request
- Telegram Data Accessed by Osascript
- Telegram Data Accessed by Unsigned or Untrusted Process
- Unusual Linux Process Calling the Metadata Service
- Unusual Linux User Calling the Metadata Service
- Unusual Web Config File Access
- Unusual Windows Process Calling the Metadata Service
- Unusual Windows User Calling the Metadata Service
- Web Server Cloud Metadata SSRF Request
- Web Server Exploitation Detected via Defend for Containers
- Web Server Local File Inclusion Activity
- Web Server Potential Command Injection Request
- Wireless Credential Dumping using Netsh Command
Splunk 47 rules
- Add DefaultUser And Password In Registry
- ADExplorer Execution (Sysmon)
- ADExplorer Execution (Windows Event Log)
- ADExplorer Snapshot Creation (Sysmon)
- ADExplorer Snapshot Creation (Windows Event Log)
- Attempted Veeam Database Credential Dump (PowerShell)
- Attempted Veeam Database Credential Dump (Sysmon)
- Attempted Veeam Database Credential Dump (Windows Event Log)
- Auto Admin Logon Registry Entry
- Cisco Isovalent - Access To Cloud Metadata Service
- Cisco SNMP Community String Configuration Changes
- Credentials in Registry (Windows Event Log)
- Detect AWS Console Login by New User
- Kubernetes Abuse of Secret by Unusual Location
- Kubernetes Abuse of Secret by Unusual User Agent
- Kubernetes Abuse of Secret by Unusual User Group
- Kubernetes Abuse of Secret by Unusual User Name
- Linux Auditd Find Ssh Private Keys
- Linux Auditd Private Keys and Certificate Enumeration
- Linux Shell History Access Via Command Line Utility
- Locate Credentials (PowerShell)
- Locate Credentials (Sysmon)
- Locate Credentials (Windows Event Log)
- MCP Github Suspicious Operation
- MCP Sensitive System File Search
- Mimikatz (Sysmon)
- Mimikatz (Windows Event Log)
- Mimikatz Execution (Windows Event Log)
- O365 Email Suspicious Search Behavior
- O365 SharePoint Suspicious Search Behavior
- Potential password in username
- Shai-Hulud 2 Exfiltration Artifact Files
- Splunk Sensitive Information Disclosure in DEBUG Logging Channels
- Windows Credentials in Registry Reg Query
- Windows Export Certificate
- Windows Findstr GPP Discovery
- Windows LAPS Password Gathering Via PowerShell Script
- Windows Post Exploitation Risk Behavior
- Windows PowerShell Export Certificate
- Windows PowerShell Export PfxCertificate
- Windows PowerSploit GPP Discovery
- Windows Private Keys Discovery
- Windows SharePoint Spinstall0 GET Request
- Windows Unsecured Outlook Credentials Access In Registry
- Windows Unusual FileZilla XML Config Access
- Windows Unusual Intelliform Storage Registry Access
- Windows WinSCP Configuration Security Access
Kusto 22 rules
- AD FS Abnormal EKU object identifier attribute
- Azure DevOps Variable Secret Not Secured
- CiscoISE - Certificate has expired
- Cross-Cloud Suspicious Compute resource creation in GCP
- Cross-Cloud Suspicious user activity observed in GCP Envourment
- Cynerio - IoT - Default password
- Cynerio - IoT - Weak password
- F&O - Unusual sign-in activity using single factor authentication
- GCP Security Command Center - Detect Open/Unrestricted API Keys
- GCP Security Command Center - Detect projects with API Keys present
- GTI - Data Leak Alert Detected
- GTI - High and Critical Priority Alerts
- GTI - High Relevance Alert Detected
- GTI - Initial Access Broker Alert Detected
- GTI - Insider Threat Alert Detected
- GTI Relevance System Alert - Incident by Alert ID
- Pathlock TDnR - LDAP Synchronization Application Log Events
- Pathlock TDnR - STRUST PSE Certificate Changes
- Powershell Empire Cmdlets Executed in Command Line
- PROD (TM010.1) - BITLOCKER - Stored Bitlocker Recovery Key to Tier Level Computer Object
- SAP BTP - Cloud Integration JDBC data source changes
- SAP BTP - Cloud Integration tampering with security material
YARA-L 6 rules
- ADFS DKM Key Access
- AWS IAM Compromised Key Quarantine Policy Attached
- GCP Service Account Key Used From Multiple Countries
- GitHub Secret Scanning Alert
- Google Workspace Encryption Key File Accessed By An Anonymous User
- OneLogin Application Password Revealed
Panther 30 rules
- AppOmni Alert Passthrough
- AWS Access Key Rotation
- AWS Compromised IAM Key Quarantine
- AWS IAM Access Key Compromise Detection
- AWS KMS CMK Key Rotation
- AWS KMS Key Restricts Usage
- AWS RDS Log File Downloaded
- AWS Secrets Manager Batch Retrieve Secrets
- AWS Secrets Manager Batch Retrieve Secrets Catch-All
- AWS Secrets Manager Retrieve Secrets Multi-Region
- Azure Storage Account Keys Listed
- Azure Storage SAS Token Access from External IP
- BETA - Sensitive 1Password Item Accessed
- Configuration Required - Sensitive 1Password Item Accessed
- Databricks TruffleHog Scan Detected
- EC2 Secrets Manager Retrieve Secrets
- GitHub Secret Scanning Alert Created
- GSuite User Password Leaked
- Kubernetes Admission Controller Webhook Created
- Kubernetes All Secrets Dumped Across Namespaces
- Kubernetes Client Certificate Credential Created
- Kubernetes Data Copy via kubectl cp
- Kubernetes Ingress Created Without TLS
- Kubernetes Long-Lived Service Account Token Created
- Kubernetes Secret Access Denied
- Kubernetes Secret Enumeration by a User
- Kubernetes Service Account Token Theft from Pod
- Okta Password Accessed
- OneLogin Password Access
- Secret Exposed and not Quarantined