What MITRE ATT&CK T1552.003: Shell History (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1552.003 (Shell History) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search the bash command history on compromised systems for insecurely stored credentials. Bash keeps track of the commands users type on the command-line with the "history" utility. Once a user logs out, the history is flushed to the user's .bash_history file. For each user, this file resides at the same location: ~/.bash_history. Typically, this file keeps track of the user's last 500 commands. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1552/003/
SHA-256 integrity: 39070ca2b8e09f48d51ca7523601f4520ffc62c527eb51b651d3016a9caf9bc5
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1552.003: Shell History (https://attack.mitre.org/techniques/T1552/003/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access