T1003.008/etc/passwd and /etc/shadow
T1003.008 — /etc/passwd and /etc/shadow is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 10 detection use cases covering it and 7 threat-intel articles citing it.
Credential Access
10Use cases
7Articles
0Sub-techniques
1Tactic
↑ Parent technique: T1003 · OS Credential Dumping