1200KM / simulation
T1552.003 Shell History — Attack Simulation
Adversaries may search the command history on compromised systems for insecurely stored credentials. On Linux and macOS systems, shells such as Bash and Zsh keep track of the commands users type on the command-line with the "history" utility. Once a user logs out, the history is flushed to the user's history file. For each user, this file resides at the same location: for example, `~/.bash_history` or `~/.zsh_history`. Typically, these files…
Technique description
Adversaries may search the command history on compromised systems for insecurely stored credentials. On Linux and macOS systems, shells such as Bash and Zsh keep track of the commands users type on the command-line with the "history" utility. Once a user logs out, the history is flushed to the user's history file. For each user, this file resides at the same location: for example, `~/.bash_history` or `~/.zsh_history`. Typically, these files…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Search Through Bash History
Procedure 3cfde62b-7c33-4b26-a61e-755d6131c8ce; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Search Through Zsh History
Procedure 8f2765a8-e795-438b-a102-5e25a7adcce1; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Search Through SQL History
Procedure ce64e135-f186-4c4a-85da-75f6ef71e46f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Search Through sh History
Procedure d87d3b94-05b4-40f2-a80f-99864ffa6803; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.