T1552 โ Unsecured Credentials
Parent technique
Description
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Sub-techniques
- T1552.001 โ Credentials In Files
- T1552.002 โ Credentials in Registry
- T1552.003 โ Shell History
- T1552.004 โ Private Keys
- T1552.005 โ Cloud Instance Metadata API
- T1552.006 โ Group Policy Preferences
- T1552.007 โ Container API
- T1552.008 โ Chat Messages
Detected by EasySIEM
This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, it shows up automatically on your own Grafana Alerts dashboard's "Top ATT&CK Techniques" panel, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.