// MITRE ATT&CK

T1552.008 · Chat Messages

🎯 Credential Access SaaSOffice Suite Sub-technique

Sub-technique of T1552 · Unsecured Credentials.

Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services th...

How to detect & mitigate it

Detecting Chat Messages starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.