T1003.008/etc/passwd and /etc/shadow
T1003.008 — /etc/passwd and /etc/shadow is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 9 detection use cases covering it and 6 threat-intel articles citing it.
Credential Access
9Use cases
6Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1003 · OS Credential Dumping