Cross-source coverage

T1552 / ATT&CK

Unsecured Credentials

303 rules · 298 families across 12 sources.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Platforms
Windows · SaaS · IaaS · Linux · macOS · Containers · Network Devices · Office Suite · Identity Provider
Telemetry
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLmacos:unifiedlogsaas:googleworkspacesaas:zoomazure:signinlogsAWS:CloudTrailcontainerd:Eventslinux:syslogNSM:Flow

How MITRE says to detect it DET0412

Detect Access or Search for Unsecured Credentials Across Platforms

Windows Analytic 1153

Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.

  • WinEventLog:Sysmon EventCode=11
  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=13, 14

Linux Analytic 1154

Reading of sensitive files like.bash_history, /etc/shadow, or private key directories by unauthorized users or unusual processes.

  • auditd:SYSCALL open/read system calls to ~/.bash_history or /etc/shadow
  • auditd:SYSCALL execution of tools like cat, grep, or awk on credential files

macOS Analytic 1155

Unusual access to ~/Library/Keychains, ~/.bash_history, or Terminal command history by unauthorized processes or users.

  • macos:unifiedlog read access to ~/Library/Keychains or history files by terminal processes
  • macos:unifiedlog execution of 'security', 'cat', or 'grep' commands accessing credential storage

SaaS Analytic 1156

Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens.

  • saas:googleworkspace Accessed third-party credential management service
  • saas:zoom unusual web session tokens and automation patterns during login

Identity Provider Analytic 1157

Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.

  • azure:signinlogs Reset password or download key from portal
  • AWS:CloudTrail GetSecretValue

Containers Analytic 1158

Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context.

  • auditd:SYSCALL read of /run/secrets or docker volumes by non-entrypoint process
  • containerd:Events unusual process spawned from container image context

Network Devices Analytic 1159

Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings.

  • linux:syslog CLI access to 'show running-config', 'show password', or 'cat config.txt'
  • NSM:Flow large transfer from management IPs to unauthorized host

Sub-techniques with coverage

Counted in the 303 above — a rule tagged a sub-technique covers this technique too.


elastic/detection-rules

89 rules
Detection Severity Format
AWS Bedrock AgentCore Execution Role Used Outside Its Runtime High Elastic TOML
AWS Bedrock AgentCore Runtime Prompt Containing Credentials High Elastic TOML
AWS Bedrock AgentCore Runtime Prompt Targeting Credentials or Instance Metadata High Elastic TOML
AWS Credentials Searched For Inside A Container High Elastic TOML
AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization High Elastic TOML
AWS EC2 Instance Console Login via Assumed Role High Elastic TOML
AWS IAM CompromisedKeyQuarantine Policy Attached to User High Elastic TOML
AWS IAM Long-Term Access Key Correlated with Elevated Detection Alerts High Elastic TOML
Azure AKS Secret get or list with Suspicious User Agent High Elastic TOML
Creation or Modification of Domain Backup DPAPI private key High Elastic TOML

+ 79 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

56 rules
Detection Severity Format
Potential Russian APT Credential Theft Activity Critical Sigma
Application AppID Uri Configuration Changes High Sigma
Cisco Crypto Commands High Sigma
Copy Passwd Or Shadow From TMP Path High Sigma
Credentials In Files High Sigma
Credentials In Files - Linux High Sigma
DPAPI Backup Keys And Certificate Export Activity IOC High Sigma
Findstr GPP Passwords High Sigma
HackTool - Typical HiveNightmare SAM File Export High Sigma
HackTool - WinPwn Execution High Sigma

+ 46 more from SigmaHQ/sigma → showing the 10 highest-severity

socfortress/Wazuh-Rules

50 rules · 47 families
Detection Severity Format
Detected rsync used to exfiltrate GnuPG directory to /tmp/GnuPG (T1552.004) High Wazuh XML
Detected rsync used to stage SSH private keys to /tmp/art-staging (T1552.004) High Wazuh XML
Detecting attempts to extract passwords with grep. 2 variants High Wazuh XML
Detects commandline operations on shell history files. 2 variants High Wazuh XML
Detects commandline operations on shell history files. 2 variants High Wazuh XML
Grep used to extract credentials - suspicious search terms (T1552.003) High Wazuh XML
Kubernetes: Attempt to read service account token via exec (T1552.007) High Wazuh XML
Kubernetes: List all secrets from all namespaces (T1552.007) High Wazuh XML
operation. · office_365.Operation = Device no longer compliant. High Wazuh XML
operation. · office_365.Operation = Remove users strong authentication phone app detail. High Wazuh XML

+ 40 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

33 rules
Detection Severity Format
Add DefaultUser And Password In Registry Undefined SPL
Auto Admin Logon Registry Entry Undefined SPL
Cisco Isovalent - Access To Cloud Metadata Service Undefined SPL
Cisco SNMP Community String Configuration Changes Undefined SPL
Detect AWS Console Login by New User Undefined SPL
Kubernetes Abuse of Secret by Unusual Location Undefined SPL
Kubernetes Abuse of Secret by Unusual User Agent Undefined SPL
Kubernetes Abuse of Secret by Unusual User Group Undefined SPL
Kubernetes Abuse of Secret by Unusual User Name Undefined SPL
Linux Auditd Find Ssh Private Keys Undefined SPL

+ 23 more from splunk/security_content → showing the 10 highest-severity

elastic/protections-artifacts

31 rules · 29 families
Detection Severity Format
Access Attempt to Non Existing Cryptocurrency Wallet Undefined Elastic TOML
Access to Browser Credentials from Suspicious Memory Undefined Elastic TOML
AutoLogons Access Attempt via Registry Undefined Elastic TOML
Bun Script Attempted to Access IMDS Metadata 2 variants Undefined Elastic TOML
Bun Script Attempted to Access IMDS Metadata 2 variants Undefined Elastic TOML
Cloud Credential Files Accessed by Osascript Undefined Elastic TOML
Cloud Credential Files Accessed by Process in Suspicious Directory Undefined Elastic TOML
Crypto Wallet File Access by Unsigned or Untrusted Binary Undefined Elastic TOML
Crypto Wallet File Access via CommandLine Undefined Elastic TOML
Crypto Wallet or Web Browser File Access via Nodejs Undefined Elastic TOML

+ 21 more from elastic/protections-artifacts → showing the 10 highest-severity

panther-labs/panther-analysis

27 rules
Detection Severity Format
Kubernetes All Secrets Dumped Across Namespaces Critical Panther Python
AWS Compromised IAM Key Quarantine High Panther Python
AWS IAM Access Key Compromise Detection High Panther Python
GSuite User Password Leaked High Panther Python
Kubernetes Service Account Token Theft from Pod High Panther Python
Secret Exposed and not Quarantined High Panther Python
AppOmni Alert Passthrough Medium Panther Python
Azure Storage Account Keys Listed Medium Panther Python
Databricks TruffleHog Scan Detected Medium Panther Python
GitHub Secret Scanning Alert Created Medium Panther Python

+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity

chronicle/detection-rules

6 rules
Detection Severity Format
adfs_dkm_key_access High YARA-L
aws_iam_compromised_key_quarantine_policy_attached High YARA-L
github_secret_scanning_alert High YARA-L
onelogin_application_password_revealed High YARA-L
google_workspace_encryption_key_files_accessed_by_anonymous_user Medium YARA-L
gcp_service_account_key_used_from_multiple_countries Low YARA-L

Azure/Azure-Sentinel

3 rules
Detection Severity Format
AD FS Abnormal EKU object identifier attribute High KQL
AI Agents - Hard-coded credentials in Tools or Configuration Undefined KQL
Users Opening and Reading the Local Device Identity Key Undefined KQL

falcosecurity/rules

3 rules
Detection Severity Format
Find AWS Credentials Medium Falco YAML
Search Private Keys or Passwords Medium Falco YAML
Contact EC2 Instance Metadata Service From Container Low Falco YAML

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Commandlines with cleartext passwords Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

Wazuh Core Ruleset

2 rules
Detection Severity Format
Powershell process created PFX file . Possible private key or certificate exportation · win.eventdata.image = (?i)powershell\.exe Medium Wazuh XML
PFX file was created · win.eventdata.targetFilename = (?i)\.pfx Low Wazuh XML

Emerging Threats Open

1 rule
Detection Severity Format
ET WEB_SPECIFIC_APPS Zoho ManageEngine OpManager Directory Traversal Attempt (CVE-2020-12116) High Suricata

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.