1200KM / detection
T1552.003 Shell History — Detection Rules
Detection workspace for T1552.003 Shell History: 3 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious History File Operations - Linux · test · medium · {"product":"linux","service":"auditd"}
- Suspicious History File Operations · test · medium · {"product":"macos","category":"process_creation"}
- Cisco Show Commands Input · test · medium · {"product":"cisco","service":"aaa"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0385 Detect Access and Parsing of .bash_history Files for Credential Harvesting
AN1085 Analytic 1085
A process outside of interactive shell context reads ~/.bash_history directly (e.g., using cat, less, grep), often shortly after privilege escalation or user switch (su/sudo). This may be followed by credential scanning in memory or file writes to new locations.
AN1086 Analytic 1086
A process or terminal command outside of standard shell utilities reads the user's .bash_history file. On macOS, unified logs or telemetry tools like EndpointSecurity (ESF) may observe file read APIs or terminal process lineage that shows non-user-initiated access.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1552.003 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.