Cross-source coverage

T1081 / ATT&CK

Credentials in Files

ATT&CK has retired this technique. Rules still tag it; the current id is T1552.001 Unsecured Credentials: Credentials In Files.

7 rules · 6 families across 2 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may search local file systems and remote file shares for files containing passwords. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

It is possible to extract passwords from backups or saved virtual machines through OS Credential Dumping. Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.

In cloud environments, authenticated user credentials are often stored in local configuration and credential files. In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.

Platforms
Windows · IaaS · Linux · macOS
Telemetry

chronicle/detection-rules

5 rules
Detection Severity Format
agenttesla_rat_detection Undefined YARA-L
a_variant_of_lokibot_trojan Undefined YARA-L
judgement_panda_exfil_activity Undefined YARA-L
possible_credential_in_files_execution_sysmon_behavior Undefined YARA-L
powershell_obfuscation_by_agenttesla Undefined YARA-L

socfortress/Wazuh-Rules

2 rules · 1 family
Detection Severity Format
Sysmon - Event 1: Process creation · Credentials in Files (T1081) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · Credentials in Files (T1081) 2 variants Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.