Compliance Node Overview
MITRE ATT&CK T1552.001 (Credentials In Files) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords. It is possible to extract passwords from backups or saved virtual machines through OS Credential Dumping. Affected platforms: Windows, IaaS, Linux, macOS, Containers. MITRE-documented mitigations include M1017 User Training, M1047 Audit, M1022 Restrict File and Directory Permissions, M1027 Password Policies. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1552/001/
SHA-256 integrity: 8892865b9dc39fbc49c89bafef211c70403e8d7e767c5aa61aaab72461e8cb6a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1552.001: Credentials In Files (https://attack.mitre.org/techniques/T1552/001/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access