Analytics BIOC Low

Extracting credentials from Unix files

Suspicious Unix files containing insecurely stored credentials were accessed.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Attacker's goals:

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.

Investigative actions:

Investigate the process activities and use of the extracted credentials.

Test period:
N/A (single event)
Deduplication:
1 Hour