Analytics BIOC Low

Reading bash command history file

Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Shell History (T1552.003)
Attacker's goals:

Adversaries may search the bash history file to search for insecurely stored credentials.

Investigative actions:

Investigate the process activities and use of the extracted credentials.

Test period:
N/A (single event)
Deduplication:
1 Day