1200KM / simulation
T1003.008 /etc/passwd and /etc/shadow — Attack Simulation
Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information, including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user. Linux stores user information such as user ID, group ID, home directory path, and login shell in /etc/passwd. A…
Technique description
Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information, including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user. Linux stores user information such as user ID, group ID, home directory path, and login shell in /etc/passwd. A…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Access /etc/shadow (Local)
Procedure 3723ab77-c546-403c-8fb4-bb577033b235; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Access /etc/master.passwd (Local)
Procedure 5076874f-a8e6-4077-8ace-9e5ab54114a5; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Access /etc/passwd (Local)
Procedure 60e860b6-8ae6-49db-ad07-5e73edd88f5d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Access /etc/{shadow,passwd,master.passwd} with a standard bin that's not cat
Procedure df1a55ae-019d-4120-bc35-94f4bc5c4b0a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Access /etc/{shadow,passwd,master.passwd} with shell builtins
Procedure f5aa6543-6cb2-4fae-b9c2-b96e14721713; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.