Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.001

T1552.001Credentials In Files

T1552.001 — Credentials In Files is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 110 detection use cases covering it and 73 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
110Use cases
73Articles
0Sub-techniques
1Tactic

Use cases covering this technique (110)

Azure Key Vault keys / secrets read Internal actions · alerting DD [WEEKLY] Cross-category credential-store enumeration with rapid egress to anonymizing tunnel/CDN Internal actions · alerting DSP [WEEKLY] Developer interpreter / package-manager process exfiltrating tokens to public code-hosting / worker domains Internal install · alerting DSPDDCSCW [WEEKLY] Dev/CI Toolchain Credential Read + Egress to Non-Canonical Registry Internal actions · alerting DSPDDCS [WEEKLY] Install-Triggered Registry Publish or Git Push (Supply-Chain Worm Self-Propagation) Internal actions · alerting DSPDDCSCW [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] npm Install-Time Lifecycle Hook Triggers Outbound Egress to Newly-Seen Domain (Shai-Hulud/Miasma/IronWorm pattern) Internal install · alerting DSPDD [WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD [WEEKLY] Package Manager / Dev-Tool Auto-Execution Triggers Non-Registry Egress or Credential-Store Access Internal install · alerting DSPDD [WEEKLY] Package-manager install hook spawns interpreter that beacons to non-registry host within 120s Internal install · alerting DSPDD [WEEKLY] Package Manager Install Hook Spawns Scripting Interpreter Then Touches Credential Files or Egresses Off-Registry Internal install · alerting DSPDD [WEEKLY] Package-Manager Install -> Interpreter Child -> Non-Registry Egress Within 5 Minutes Internal install · alerting DSPDD [WEEKLY] Package-manager install-time interpreter spawn with credential-file read and outbound egress within 120s Internal install · alerting DSPDD [WEEKLY] Package manager lifecycle hook spawns network-fetching shell or runtime Internal install · alerting DSΣPDD [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD [WEEKLY] Web-tier interpreter post-exploitation: shell/net-tool spawn, secret-file read, or cloud IMDS reach Internal install · alerting DSΣPDDCSCW MCP Github Suspicious Operation ESCU actions · hunting P MCP Sensitive System File Search ESCU actions · hunting P Potential password in username ESCU actions · hunting P Shai-Hulud 2 Exfiltration Artifact Files ESCU actions · alerting P Windows Unusual FileZilla XML Config Access ESCU actions · hunting P Windows Unusual Intelliform Storage Registry Access ESCU actions · hunting P Windows WinSCP Configuration Security Access ESCU actions · hunting P [LLM] conflibot post-injection secret exfiltration: token grab by git/shell child on CI runner (CVE-2026-55158) Bespoke actions · hunting DSΣPDDCS [LLM] vmdir credential theft via /tmp/.vmware-perf-upd.sh and vmafd module Bespoke exploit · hunting DSΣPDDCS [LLM] TeamPCP Cloud Stealer reading CI runner process memory via /proc/<pid>/mem Bespoke actions · hunting DSΣPDDCS [LLM] ChainDrop IMDS credential theft: node/bun reading cloud instance metadata (169.254.169.254 / 169.254.170.2) Bespoke actions · hunting DSΣPDDCS [LLM] Access to Flowise credential store /root/.flowise and secret env vars Bespoke actions · hunting DSΣPDDCS [LLM] Bun runtime executing Shai-Hulud Math_Symbol.js credential stealer Bespoke actions · alerting DSΣPDDCS [LLM] npm-install child process reading developer credential stores (keyv stealer) Bespoke actions · hunting DSΣPDDCS [LLM] Vulnerable Pterodactyl Wings node (< v1.12.3) exposed to CVE-2026-52855 config-secret disclosure Bespoke exploit · hunting DSP [LLM] Pterodactyl Wings daemon-token file (/etc/pterodactyl/config.yml) read by non-Wings process Bespoke actions · hunting DSΣPDDCS [LLM] anthropickit exfiltration POST to Pipedream endpoint (enqqnvvtgrnyl.x.pipedream.net) Bespoke actions · alerting DSΣPCS [LLM] Rails web process reads /proc/self/environ or app secrets (Active Storage libvips file-read) Bespoke actions · hunting SPCS [LLM] Recon tool reading K8s service-account token or /proc/self/environ inside a container Bespoke recon · hunting DSΣPDDCS [LLM] Python interpreter reading SSH + AWS + Kube credential stores Bespoke actions · hunting DSPCS [LLM] CI runner process POSTing secrets to GhostAction exfil host via curl/wget/node Bespoke actions · alerting DSΣPDDCS [LLM] Build/attestation process egress to non-canonical OCI registry (@sigstore/oci cred leak, CVE-2026-59891) Bespoke actions · hunting DSPCS [LLM] actions/attest push-to-registry invocation using @sigstore/oci — externally influenced destination (CVE-2026-59891) Bespoke actions · hunting DSΣPDDCS [LLM] Build/attestation tooling reading ~/.docker/config.json (credential harvest surface, CVE-2026-59891) Bespoke actions · hunting DSΣPCS [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] Envoy Gateway ServiceAccount token reuse for anomalous K8s API actions Bespoke actions · hunting SΣPDD [LLM] Shai-Hulud credential exfiltration: node/npm outbound to webhook.site Bespoke actions · alerting DSΣPDDCS [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC dirac.cfg/proxy access followed by outbound egress from service process (exfiltration) Bespoke actions · alerting DSPCS [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) Bespoke actions · hunting DSΣPDDCS [LLM] Backdoored @injectivelabs/sdk-ts 1.20.21 payload file dropped on disk Bespoke install · hunting DSΣPDDCS [LLM] TruffleHog secret scanner spawned from an npm/bun package-install context (Sha1-Hulud) Bespoke actions · hunting DSΣPDDCS [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] TruffleHog secret-scanning spawned by npm/pip during install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] Worm propagation: burst of npm/PyPI publishes from a developer machine Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scan spawned by npm/node install (Shai-Hulud credential harvest) Bespoke actions · hunting DSΣPDDCS [LLM] Node child of node-gyp/python making outbound to GitHub dead-drop or anomalous web service during install Bespoke exfil · hunting DSPDDCS [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: postinstall bundle.js spawns TruffleHog secret scan Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud npm worm: secret exfiltration to hardcoded webhook.site endpoint Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host Bespoke actions · alerting DSΣPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] npm/yarn/pnpm postinstall hook spawning credential-harvest tooling Bespoke install · hunting DSΣPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] npm/bun process writing GitHub Actions workflow files (worm secret-exfil injection) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Single process fan-out reading cloud, Vault, SSH and AI-tool credential files Bespoke actions · hunting DSPCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc Bespoke actions · hunting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Mini Shai-Hulud known SHA256 IOC match (setup.mjs / execution.js / runner-memory dumper) Bespoke install · hunting DSΣPDD [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] Credential archive staging — trin.tar.gz created by python process Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud preinstall: node/npm spawning git/curl/gh pushing to attacker repo or GitHub API Bespoke actions · hunting DSPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Exfiltration to kubernetes-el attacker webhook.site UUIDs (Pwn Request payload) Bespoke c2 · alerting DSΣPDD [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Local AI coding agents (claude/gemini/q) launched with permission-bypass flags during package install — s1ngularity Bespoke install · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] AI agent skill leaks Stripe key or card PAN/CVC verbatim in curl command line Bespoke actions · alerting DSΣPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] AI agent skill exfiltrates GitHub token / env secrets via dynamic-context shell-out Bespoke actions · alerting DSΣPDDCS [LLM] Shai-Hulud 3.0 'Goldox-T3chs' GitHub exfiltration marker observed Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Runner.Worker process memory dumped via /proc/PID/mem read on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Assets running vulnerable crypto-js (<4.2.0) or crypto-es (<2.1.0) — CVE-2023-46233 / CVE-2023-46133 Bespoke exploit · hunting DSP [LLM] Storage account key retrieval (listKeys) inside an ARM/Bicep deployment — secret-in-output leak vector Bespoke actions · hunting SPDD [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file Bespoke actions · alerting DSΣPDDCS [LLM] Environment-variable exfiltration to hacktask C2 (npm.hacktask.net) Bespoke c2 · alerting DSΣPDDCS [LLM] Gradle plugin-publish run with verbose logging leaks pre-signed AWS URL (CVE-2020-7599) Bespoke recon · hunting DSΣPDDCS

Articles citing this technique (73)