Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1003.007

T1003.007Proc Filesystem

T1003.007 — Proc Filesystem is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 8 detection use cases covering it and 8 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
8Articles
0Sub-techniques
1Tactic

Use cases covering this technique (8)

[LLM] Credential harvest via /proc/<pid>/mem read of GitHub Actions Runner.Worker Bespoke actions · hunting DSΣPDDCS [LLM] GitHub Actions Runner.Worker memory read via /proc/<pid>/mem (CI secret unmasking) Bespoke actions · alerting DSΣPDDCS [LLM] Runner.Worker process memory scrape via /proc on self-hosted GitHub Actions runner Bespoke actions · alerting DSΣPDDCS [LLM] CI runner secret theft via /proc/<pid>/mem read of Runner.Worker (Miasma memory scraper) Bespoke actions · hunting SΣPCS [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) Bespoke actions · alerting DSΣPDDCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc Bespoke actions · hunting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD

Articles citing this technique (8)