Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0446 — Credential Access via /etc/passwd and /etc/shadow Parsing
DET0446

Credential Access via /etc/passwd and /etc/shadow Parsing

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1234 Analytic 1234
Linux

Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users.

auditd:SYSCALL open, read auditd:SYSCALL execve
[exe] Executable name used to access credentials (e.g., cat, cp, awk); can vary across environments
[user] User context under which the access occurs; typically root, but can be non-standard in attacks
[PATH] Target file paths (e.g., /etc/passwd, /etc/shadow); may vary in containerized or customized systems
[TimeWindow] Time correlation threshold for chaining access and execution events

Detected Techniques

1

Details

MITRE ID
DET0446
STIX ID
x-mitre-detection-strategy--17c97a51-74c2-449c-bc95-cf6a7647fb83
Analytics
1
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.