1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1552 Unsecured Credentials — Detection Rules

Detection workspace for T1552 Unsecured Credentials: 12 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1552 Unsecured Credentials

MATCH(file_content_or_path_matches_credential_pattern) OR MATCH(secret_retrieval BY unauthorized_identity) -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0412 Detect Access or Search for Unsecured Credentials Across Platforms

AN1153 Analytic 1153

Unusual access to bash history, registry credentials paths, or private key files by unauthorized or scripting tools, with correlated file and process activity.

AN1154 Analytic 1154

Reading of sensitive files like .bash_history, /etc/shadow, or private key directories by unauthorized users or unusual processes.

AN1155 Analytic 1155

Unusual access to ~/Library/Keychains, ~/.bash_history, or Terminal command history by unauthorized processes or users.

AN1156 Analytic 1156

Unusual web-based access or API scraping of password managers, single sign-on sessions, or credential sync services via browser automation or anomalous API tokens.

AN1157 Analytic 1157

Unauthorized API or console calls to retrieve or reset password credentials, download key material, or modify SSO settings.

AN1158 Analytic 1158

Access to container image layers or mounted secrets (e.g., Docker secrets) by processes not tied to entrypoint or orchestration context.

AN1159 Analytic 1159

Use of configuration backup utilities or CLI access to dump plaintext passwords, local user hashes, or SNMP strings.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1552 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.