Compliance Node Overview
MITRE ATT&CK T1552.008 (Chat Messages) is an Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat communication applications such as email, chat services like Slack or Teams, collaboration tools like Jira or Trello, and any other services that support user communication. Users may share various forms of credentials (such as usernames and passwords, API keys, or authentication tokens) on private or public corporate internal communications channels. Affected platforms: SaaS, Office Suite. MITRE-documented mitigations include M1047 Audit, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, AC-18.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1552/008/
SHA-256 integrity: 75e0436f03ad538589234d80e89141ce8ef2b654604e5066eae66a7d70bc659a
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1552.008: Chat Messages (https://attack.mitre.org/techniques/T1552/008/)
- MITRE ATT&CK Tactic TA0006: Credential Access (https://attack.mitre.org/tactics/TA0006/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access