Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.001

T1552.001Credentials In Files

T1552.001 — Credentials In Files is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 110 detection use cases covering it and 74 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
110Use cases
74Articles
0Sub-techniques
1Tactic

Use cases covering this technique (110)

Azure Key Vault keys / secrets read Internal actions · alerting DD [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD MCP Github Suspicious Operation ESCU actions · hunting P MCP Sensitive System File Search ESCU actions · hunting P Potential password in username ESCU actions · hunting P Shai-Hulud 2 Exfiltration Artifact Files ESCU actions · alerting P Windows Unusual FileZilla XML Config Access ESCU actions · hunting P Windows Unusual Intelliform Storage Registry Access ESCU actions · hunting P Windows WinSCP Configuration Security Access ESCU actions · hunting P [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) Bespoke actions · alerting SΣPCS [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores Bespoke actions · alerting DSΣPDDCS [LLM] Python interpreter reading SSH + AWS + Kube credential stores Bespoke actions · hunting DSPCS [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node Bespoke actions · alerting DSΣPDDCS [LLM] Build/attestation process egress to non-canonical OCI registry (@sigstore/oci cred leak, CVE-2026-59891) Bespoke actions · hunting DSPCS [LLM] actions/attest push-to-registry invocation using @sigstore/oci — externally influenced destination (CVE-2026-59891) Bespoke actions · hunting DSΣPDDCS [LLM] Build/attestation tooling reading ~/.docker/config.json (credential harvest surface, CVE-2026-59891) Bespoke actions · hunting DSΣPCS [LLM] BitLocker recovery key harvesting via manage-bde -protectors -get Bespoke actions · hunting DSΣPDDCS [LLM] CAV3RN AzureCommunication.dll config file 'logAzure.txt' written to disk Bespoke install · alerting DSΣPDDCS [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions Bespoke actions · hunting SΣPDD [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site Bespoke actions · alerting DSΣPDDCS [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC dirac.cfg/proxy access followed by outbound egress from service process (exfiltration) Bespoke actions · alerting DSPCS [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) Bespoke actions · hunting DSΣPDDCS [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] TruffleHog secret scanner spawned from an npm/bun package-install context (Sha1-Hulud) Bespoke actions · hunting DSΣPDDCS [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] 9router credential dump via GET /api/settings/database (CVE-2026-55500) Bespoke actions · alerting SΣP [LLM] 9router API-key leak via unauthenticated GET /api/usage/stats and /api/usage/request-logs Bespoke actions · alerting SΣP [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) Bespoke actions · hunting DSΣPDDCS [LLM] 9router API key / secret exfiltration via /api/settings/database without prior login Bespoke actions · alerting SP [LLM] GravitLauncher LaunchServer secret read via unauth path traversal (ecdsa_id/legacySalt/LaunchServer.json) Bespoke exploit · alerting SΣP [LLM] TruffleHog secret-scanning spawned by npm/pip during install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] Worm propagation: burst of npm/PyPI publishes from a developer machine Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install Bespoke exfil · hunting DSPDDCS [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: secret exfiltration to hardcoded webhook.site endpoint Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host Bespoke actions · alerting DSΣPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling Bespoke install · hunting DSΣPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] npm/bun process writing GitHub Actions workflow files (worm secret-exfil injection) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Single process fan-out reading cloud, Vault, SSH and AI-tool credential files Bespoke actions · hunting DSPCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc Bespoke actions · hunting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) Bespoke install · hunting DSΣPDD [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] Credential archive staging — trin.tar.gz created by python process Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity Bespoke install · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Runner.Worker process memory dumped via /proc/PID/mem read on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Assets running vulnerable crypto-js (<4.2.0) or crypto-es (<2.1.0) — CVE-2023-46233 / CVE-2023-46133 Bespoke exploit · hunting DSP [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file Bespoke actions · alerting DSΣPDDCS [LLM] Environment-variable exfiltration to hacktask C2 (npm.hacktask.net) Bespoke c2 · alerting DSΣPDDCS [LLM] Gradle plugin-publish run with verbose logging leaks pre-signed AWS URL (CVE-2020-7599) Bespoke recon · hunting DSΣPDDCS

Articles citing this technique (74)