1200KM / simulation
T1003.007 Proc Filesystem — Attack Simulation
Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc//maps` file shows how memory is mapped within the process’s virtual address space. And `/proc//mem`, exposed for debugging purposes, provides access to the process’s virtual address space. When executing with…
Technique description
Adversaries may gather credentials from the proc filesystem or `/proc`. The proc filesystem is a pseudo-filesystem used as an interface to kernel data structures for Linux based systems managing virtual memory. For each process, the `/proc//maps` file shows how memory is mapped within the process’s virtual address space. And `/proc//mem`, exposed for debugging purposes, provides access to the process’s virtual address space. When executing with…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Dump individual process memory with Python (Local)
Procedure 437b2003-a20d-4ed8-834c-4964f24eec63; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump individual process memory with sh (Local)
Procedure 7e91138a-8e74-456d-a007-973d67a0bb80; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Capture Passwords with MimiPenguin
Procedure a27418de-bdce-4ebd-b655-38f04842bf0c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Dump individual process memory with sh on FreeBSD (Local)
Procedure fa37b633-e097-4415-b2b8-c5bf4c86e423; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.