Common Information
Type Value
Value
Credentials in Files - T1081
Category Attack-Pattern
Type Mitre-Enterprise-Attack-Attack-Pattern
Misp Type Cluster
Description Adversaries may search local file systems and remote file shares for files containing passwords. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through Credential Dumping. (Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller. (Citation: SRD GPP) Detection: While detecting adversaries accessing these files may be difficult without knowing they exist in the first place, it may be possible to detect adversary use of credentials they have obtained. Monitor the command-line arguments of executing processes for suspicious words or regular expressions that may indicate searching for a password (for example: password, pwd, login, secure, or credentials). See Valid Accounts for more information. Platforms: Linux, macOS, Windows Data Sources: File monitoring, Process command-line parameters Permissions Required: User, Administrator, SYSTEM System Requirements: Access to files
Details Published Attributes CTI Title
Details Website 2023-07-07 5 Malware Analysis - ransomware - 99a4a7145a78577d18ab6547210e5fec - RedPacket Security
Details Website 2023-07-04 12 Malware Analysis - djvu - ca1a0dd10f4376823f81798a4a338be2 - RedPacket Security
Details Website 2023-06-30 10 Malware Analysis - ransomware - 26156564a104eae0cc9b06306a63ed9a - RedPacket Security
Details Website 2023-06-29 12 Malware Analysis - amadey - e7dce44fd1c02623719da154a73530b2 - RedPacket Security
Details Website 2023-06-29 7 Malware Analysis - bianlian_ransomware - e625ef18487a37a71b489d39c65a343a - RedPacket Security
Details Website 2023-06-29 4 Malware Analysis - ransomware - 0c8e88877383ccd23a755f429006b437 - RedPacket Security
Details Website 2023-06-29 12 Malware Analysis - medusalocker - f6f120d1262b88f79debb5d848ac7db9 - RedPacket Security
Details Website 2023-06-29 15 Malware Analysis - wannacry - e4df89514610e82a6884fd92ddab45f8 - RedPacket Security
Details Website 2023-06-24 11 Malware Analysis - djvu - 422df6f974e6c96bbb46e402f81a234e - RedPacket Security
Details Website 2023-06-24 11 Malware Analysis - djvu - 1353718fe77eeeeefc45a6d7a45b48d3 - RedPacket Security
Details Website 2023-06-23 11 Malware Analysis - djvu - ead225734ff9814142fa6ba8339b7e85 - RedPacket Security
Details Website 2023-06-23 11 Malware Analysis - djvu - dc4529c58230f2a089ae6cd1bf99769e - RedPacket Security
Details Website 2023-06-23 11 Malware Analysis - evasion - 31ed190022685b6533d174fd5e042b83 - RedPacket Security
Details Website 2023-06-23 11 Malware Analysis - evasion - 47bd2deca914a1687586f1532cd17c20 - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - djvu - e0227bb951b0bd76d3a21ba42abd3574 - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - djvu - 2a3f36cc1fd1f55dc98fd6592cd5d80a - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - djvu - 45841d5084e8b6dcb2cae5f631abf9d0 - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - djvu - 9a978ce2ff697915c879d31785b37e16 - RedPacket Security
Details Website 2023-06-22 12 Malware Analysis - persistence - 52105eaff1b7b02bf950b80771e9bda9 - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - djvu - d66da7cdb4b5e5f5b18d686da4ea9d5c - RedPacket Security
Details Website 2023-06-22 12 Malware Analysis - persistence - a84957660902eb17fd021f3d187fb787 - RedPacket Security
Details Website 2023-06-22 11 Malware Analysis - evasion - 642dbe8b752b0dc735e9422d903e0e97 - RedPacket Security
Details Website 2023-06-17 11 Malware Analysis - djvu - e88948bf9115d1096f89bb4bf131bff0 - RedPacket Security
Details Website 2023-06-17 11 Malware Analysis - djvu - 14ea6ebc268d3c0b4009c8fe985ec39c - RedPacket Security
Details Website 2023-06-07 20 Onyx Ransomware Report - CYFIRMA