Cross-source coverage
T1552 / ATT&CK
Unsecured Credentials
303 rules · 298 families across 12 sources.
2 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
- Tactics
- Credential Access
- Platforms
- Windows · SaaS · IaaS · Linux · macOS · Containers · Network Devices · Office Suite · Identity Provider
- Telemetry
-
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLmacos:unifiedlogsaas:googleworkspacesaas:zoomazure:signinlogsAWS:CloudTrailcontainerd:Eventslinux:syslogNSM:Flow
How MITRE says to detect it DET0412
Detect Access or Search for Unsecured Credentials Across Platforms
Windows Analytic 1153
Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.
WinEventLog:SysmonEventCode=11WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=13, 14
Linux Analytic 1154
Reading of sensitive files like.bash_history, /etc/shadow, or private key directories by unauthorized users or unusual processes.
auditd:SYSCALLopen/read system calls to ~/.bash_history or /etc/shadowauditd:SYSCALLexecution of tools like cat, grep, or awk on credential files
macOS Analytic 1155
Unusual access to ~/Library/Keychains, ~/.bash_history, or Terminal command history by unauthorized processes or users.
macos:unifiedlogread access to ~/Library/Keychains or history files by terminal processesmacos:unifiedlogexecution of 'security', 'cat', or 'grep' commands accessing credential storage
SaaS Analytic 1156
Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens.
saas:googleworkspaceAccessed third-party credential management servicesaas:zoomunusual web session tokens and automation patterns during login
Identity Provider Analytic 1157
Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.
azure:signinlogsReset password or download key from portalAWS:CloudTrailGetSecretValue
Containers Analytic 1158
Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context.
auditd:SYSCALLread of /run/secrets or docker volumes by non-entrypoint processcontainerd:Eventsunusual process spawned from container image context
Network Devices Analytic 1159
Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings.
linux:syslogCLI access to 'show running-config', 'show password', or 'cat config.txt'NSM:Flowlarge transfer from management IPs to unauthorized host
Sub-techniques with coverage
Counted in the 303 above — a rule tagged a sub-technique covers this technique too.
elastic/detection-rules
89 rules| Detection | Severity | Format |
|---|---|---|
| AWS Bedrock AgentCore Execution Role Used Outside Its Runtime | High | Elastic TOML |
| AWS Bedrock AgentCore Runtime Prompt Containing Credentials | High | Elastic TOML |
| AWS Bedrock AgentCore Runtime Prompt Targeting Credentials or Instance Metadata | High | Elastic TOML |
| AWS Credentials Searched For Inside A Container | High | Elastic TOML |
| AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization | High | Elastic TOML |
| AWS EC2 Instance Console Login via Assumed Role | High | Elastic TOML |
| AWS IAM CompromisedKeyQuarantine Policy Attached to User | High | Elastic TOML |
| AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts | High | Elastic TOML |
| Azure AKS Secret get or list with Suspicious User Agent | High | Elastic TOML |
| Creation or Modification of Domain Backup DPAPI private key | High | Elastic TOML |
+ 79 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
56 rules| Detection | Severity | Format |
|---|---|---|
| Potential Russian APT Credential Theft Activity | Critical | Sigma |
| Application AppID Uri Configuration Changes | High | Sigma |
| Cisco Crypto Commands | High | Sigma |
| Copy Passwd Or Shadow From TMP Path | High | Sigma |
| Credentials In Files | High | Sigma |
| Credentials In Files - Linux | High | Sigma |
| DPAPI Backup Keys And Certificate Export Activity IOC | High | Sigma |
| Findstr GPP Passwords | High | Sigma |
| HackTool - Typical HiveNightmare SAM File Export | High | Sigma |
| HackTool - WinPwn Execution | High | Sigma |
+ 46 more from SigmaHQ/sigma → showing the 10 highest-severity
socfortress/Wazuh-Rules
50 rules · 47 families| Detection | Severity | Format |
|---|---|---|
| Detected rsync used to exfiltrate GnuPG directory to /tmp/GnuPG (T1552.004) | High | Wazuh XML |
| Detected rsync used to stage SSH private keys to /tmp/art-staging (T1552.004) | High | Wazuh XML |
| Detecting attempts to extract passwords with grep. 2 variants | High | Wazuh XML |
| Detects commandline operations on shell history files. 2 variants | High | Wazuh XML |
| Detects commandline operations on shell history files. 2 variants | High | Wazuh XML |
| Grep used to extract credentials - suspicious search terms (T1552.003) | High | Wazuh XML |
| Kubernetes: Attempt to read service account token via exec (T1552.007) | High | Wazuh XML |
| Kubernetes: List all secrets from all namespaces (T1552.007) | High | Wazuh XML |
| operation. · office_365.Operation = Device no longer compliant. | High | Wazuh XML |
| operation. · office_365.Operation = Remove users strong authentication phone app detail. | High | Wazuh XML |
+ 40 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
33 rules| Detection | Severity | Format |
|---|---|---|
| Add DefaultUser And Password In Registry | Undefined | SPL |
| Auto Admin Logon Registry Entry | Undefined | SPL |
| Cisco Isovalent - Access To Cloud Metadata Service | Undefined | SPL |
| Cisco SNMP Community String Configuration Changes | Undefined | SPL |
| Detect AWS Console Login by New User | Undefined | SPL |
| Kubernetes Abuse of Secret by Unusual Location | Undefined | SPL |
| Kubernetes Abuse of Secret by Unusual User Agent | Undefined | SPL |
| Kubernetes Abuse of Secret by Unusual User Group | Undefined | SPL |
| Kubernetes Abuse of Secret by Unusual User Name | Undefined | SPL |
| Linux Auditd Find Ssh Private Keys | Undefined | SPL |
+ 23 more from splunk/security_content → showing the 10 highest-severity
elastic/protections-artifacts
31 rules · 29 families| Detection | Severity | Format |
|---|---|---|
| Access Attempt to Non Existing Cryptocurrency Wallet | Undefined | Elastic TOML |
| Access to Browser Credentials from Suspicious Memory | Undefined | Elastic TOML |
| AutoLogons Access Attempt via Registry | Undefined | Elastic TOML |
| Bun Script Attempted to Access IMDS Metadata 2 variants | Undefined | Elastic TOML |
| Bun Script Attempted to Access IMDS Metadata 2 variants | Undefined | Elastic TOML |
| Cloud Credential Files Accessed by Osascript | Undefined | Elastic TOML |
| Cloud Credential Files Accessed by Process in Suspicious Directory | Undefined | Elastic TOML |
| Crypto Wallet File Access by Unsigned or Untrusted Binary | Undefined | Elastic TOML |
| Crypto Wallet File Access via CommandLine | Undefined | Elastic TOML |
| Crypto Wallet or Web Browser File Access via Nodejs | Undefined | Elastic TOML |
+ 21 more from elastic/protections-artifacts → showing the 10 highest-severity
panther-labs/panther-analysis
27 rules| Detection | Severity | Format |
|---|---|---|
| Kubernetes All Secrets Dumped Across Namespaces | Critical | Panther Python |
| AWS Compromised IAM Key Quarantine | High | Panther Python |
| AWS IAM Access Key Compromise Detection | High | Panther Python |
| GSuite User Password Leaked | High | Panther Python |
| Kubernetes Service Account Token Theft from Pod | High | Panther Python |
| Secret Exposed and not Quarantined | High | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| Azure Storage Account Keys Listed | Medium | Panther Python |
| Databricks TruffleHog Scan Detected | Medium | Panther Python |
| GitHub Secret Scanning Alert Created | Medium | Panther Python |
+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity
chronicle/detection-rules
6 rules| Detection | Severity | Format |
|---|---|---|
| adfs_dkm_key_access | High | YARA-L |
| aws_iam_compromised_key_quarantine_policy_attached | High | YARA-L |
| github_secret_scanning_alert | High | YARA-L |
| onelogin_application_password_revealed | High | YARA-L |
| google_workspace_encryption_key_files_accessed_by_anonymous_user | Medium | YARA-L |
| gcp_service_account_key_used_from_multiple_countries | Low | YARA-L |
Azure/Azure-Sentinel
3 rules| Detection | Severity | Format |
|---|---|---|
| AD FS Abnormal EKU object identifier attribute | High | KQL |
| AI Agents - Hard-coded credentials in Tools or Configuration | Undefined | KQL |
| Users Opening and Reading the Local Device Identity Key | Undefined | KQL |
falcosecurity/rules
3 rules| Detection | Severity | Format |
|---|---|---|
| Find AWS Credentials | Medium | Falco YAML |
| Search Private Keys or Passwords | Medium | Falco YAML |
| Contact EC2 Instance Metadata Service From Container | Low | Falco YAML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Commandlines with cleartext passwords | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
Wazuh Core Ruleset
2 rules| Detection | Severity | Format |
|---|---|---|
| Powershell process created PFX file . Possible private key or certificate exportation · win.eventdata.image = (?i)powershell\.exe | Medium | Wazuh XML |
| PFX file was created · win.eventdata.targetFilename = (?i)\.pfx | Low | Wazuh XML |
Emerging Threats Open
1 rule| Detection | Severity | Format |
|---|---|---|
| ET WEB_SPECIFIC_APPS Zoho ManageEngine OpManager Directory Traversal Attempt (CVE-2020-12116) | High | Suricata |