// MITRE ATT&CK
T1552 · Unsecured Credentials
Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applicatio...
How to detect & mitigate it
Detecting Unsecured Credentials starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.
Sub-techniques (8)
T1552.001
Credentials In Files T1552.002
Credentials in Registry T1552.003
Shell History T1552.004
Private Keys T1552.005
Cloud Instance Metadata API T1552.006
Group Policy Preferences T1552.007
Container API T1552.008
Chat Messages
Credentials In Files T1552.002
Credentials in Registry T1552.003
Shell History T1552.004
Private Keys T1552.005
Cloud Instance Metadata API T1552.006
Group Policy Preferences T1552.007
Container API T1552.008
Chat Messages
Related techniques
T1557
Adversary-in-the-Middle T1110.001
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking
Adversary-in-the-Middle T1110.001
Password Guessing T1003
OS Credential Dumping T1539
Steal Web Session Cookie T1003.002
Security Account Manager T1552.005
Cloud Instance Metadata API T1555.002
Securityd Memory T1110.002
Password Cracking
Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.