1200KM / simulation
T1552.001 Credentials In Files — Attack Simulation
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS…
Technique description
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WinPwn - passhunt
Procedure 00e3e3c7-6c3c-455e-bd4b-461c7f0e7797; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- List Credential Files via PowerShell
Procedure 0d4f2281-f720-4572-adc8-d5bb1618affe; elevation required; cleanup not declared. Not executed or individually validated.
- Extracting passwords with findstr
Procedure 0e56bf29-ff49-4ea5-9af4-3b81283fd513; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - sensitivefiles
Procedure 114dd4e3-8d1c-4ea7-bb8d-8d8f6aca21f0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find Kubernetes user configuration files
Procedure 14575d1f-16b3-4a0b-8986-540e42e6a6cc; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Access Jenkinsfile
Procedure 18318786-e0c0-4bdf-979f-f022e6f5f2ef; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find HashiCorp Vault token files
Procedure 2951c09f-b4f9-4248-ba75-6373709ebd55; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find npm registry credential files
Procedure 2a24627b-061b-43e6-bece-a5b0638841dd; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Access unattend.xml
Procedure 367d4004-5fc0-446d-823f-960c74ae52c3; elevation required; cleanup not declared. Not executed or individually validated.
- Find AWS credentials
Procedure 37807632-d3da-442e-8c2e-00f44928ff8f; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Dump GitHub Actions Runner Environment Variables from procfs
Procedure 51cde30c-0311-449a-8e15-542b59f95939; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Access Travis CI Config File
Procedure 5312c7c3-775b-4437-a8b0-914b30cfebd4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find Docker credentials
Procedure 5a668739-3a2f-4265-895f-c0e1e0b09eaa; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - powershellsensitive
Procedure 75f66e03-37d3-4704-9520-3210efbe33ce; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Access Gitlab CI Config File
Procedure 98618067-a2c7-4d4b-9c89-403a90f43656; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find OCI credentials
Procedure 9d9c22c9-fa97-4008-a204-478cf68c40af; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Extract Browser and System credentials with LaZagne
Procedure 9e507bb8-1d30-4e3b-a49b-cb5727d7ea79; elevation required; cleanup not declared. Not executed or individually validated.
- Access Drone CI Config File
Procedure a11f22fb-a037-4cc2-bcfc-a133b287aa1b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find Azure credentials
Procedure a8f6148d-478a-4f43-bc62-5efee9f931a4; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find GCP credentials
Procedure aa12eb29-2dbb-414e-8b20-33d34af93543; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials
Procedure aaa87b0e-5232-4649-ae5c-f1724a4b2798; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find Kubernetes cluster configuration files
Procedure af664fc0-0772-4866-a661-d49a22a13487; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- List Credential Files via Command Prompt
Procedure b0cdacf6-8949-4ffe-9274-a9643a788e55; elevation required; cleanup not declared. Not executed or individually validated.
- Find .env Files Containing Application Credentials
Procedure bcf8e58a-1cb7-4988-9227-3d3c70751811; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Extract passwords with grep
Procedure bd4cf0d1-7646-474e-8610-78ccf5a097c4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find Terraform credential files
Procedure c3372ae9-b9bf-427a-b330-cb04fecb9c1d; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Search for Git Credential Files
Procedure c8367142-cbb0-47a4-96c7-ff9969fd64ea; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - SessionGopher
Procedure c9dc9de3-f961-4284-bd2d-f959c9f9fda5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find system database configuration files
Procedure d1665562-c389-49fc-9cbe-92236816a105; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Find and Access Github Credentials
Procedure da4f751a-020b-40d7-b9ff-d433b7799803; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find database credential files
Procedure e62bccc4-0200-47e9-b40a-4ea5328495b3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Snaffler
Procedure fdd0c913-714b-4c13-b40f-1824d6c015f2; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.