T1552 Unsecured Credentials — ATT&CK Technique
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).
Detection coverage (22)
- EventLog Query Requests By Builtin Utilities medium
- Kubernetes Admission Controller Modification medium
- Azure Keyvault Key Modified or Deleted medium
- Azure Key Vault Modified or Deleted medium
- Azure Keyvault Secrets Modified or Deleted medium
- Azure Kubernetes Admission Controller medium
- Application AppID Uri Configuration Changes high
- Added Owner To Application medium
- Google Cloud Kubernetes Admission Controller medium
- Potential Okta Password in AlternateID Field high
- Script Interpreter Spawning Credential Scanner - Linux high
- Potentially Suspicious EventLog Recon Activity Using Log Query Utilities medium
- Script Interpreter Spawning Credential Scanner - Windows high
- Splunk Sensitive Information Disclosure in DEBUG Logging Channels
- Detect AWS Console Login by New User
- O365 Email Suspicious Search Behavior
- O365 SharePoint Suspicious Search Behavior
- Windows LAPS Password Gathering Via PowerShell Script
- Windows Post Exploitation Risk Behavior
- Windows Unsecured Outlook Credentials Access In Registry
- Cisco SNMP Community String Configuration Changes
- Windows SharePoint Spinstall0 GET Request