Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1003.008

T1003.008/etc/passwd and /etc/shadow

T1003.008 — /etc/passwd and /etc/shadow is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 10 detection use cases covering it and 7 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
10Use cases
7Articles
0Sub-techniques
1Tactic

Use cases covering this technique (10)

ESXi Sensitive Files Accessed ESCU actions · alerting P Linux Auditd Possible Access To Credential Files ESCU actions · hunting P Linux Possible Access To Credential Files ESCU actions · hunting P [LLM] cgi-io path traversal reading root files — CVE-2026-62947 Bespoke actions · alerting SP [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Pistache CVE-2022-26068 path traversal reading /etc/passwd via /doc/../ Bespoke exploit · alerting SΣP [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) Bespoke actions · alerting SΣPCS [LLM] Dirty Pipe (CVE-2022-0847): /etc/passwd or /etc/shadow modified by unexpected process Bespoke exploit · alerting DSΣPCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS

Articles citing this technique (7)