Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552.004

T1552.004Private Keys

T1552.004 — Private Keys is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 23 detection use cases covering it and 13 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
23Use cases
13Articles
0Sub-techniques
1Tactic

Use cases covering this technique (23)

[WEEKLY] npm/yarn/pnpm Install-Hook Spawn → Credential-Store Read or Worm-Payload Drop in node_modules Internal install · alerting DSΣPDD [WEEKLY] Package-install lifecycle script harvests local credentials and beacons to a non-baselined domain Internal install · alerting DSPDD [WEEKLY] Package-manager child process credential fan-out with public egress (Mini Shai-Hulud / TeamPCP worm chain) Internal install · alerting DSPDD Linux Auditd Find Ssh Private Keys ESCU actions · hunting P Linux Auditd Private Keys and Certificate Enumeration ESCU actions · hunting P Windows Export Certificate ESCU actions · hunting P Windows PowerShell Export Certificate ESCU actions · hunting P Windows PowerShell Export PfxCertificate ESCU actions · hunting P Windows Private Keys Discovery ESCU actions · hunting P Linux Auditd Find Private Keys ESCU actions · alerting P [LLM] Python interpreter reading SSH + AWS + Kube credential stores Bespoke actions · hunting DSPCS [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) Bespoke actions · hunting DSΣPDDCS [LLM] GravitLauncher LaunchServer secret read via unauth path traversal (ecdsa_id/legacySalt/LaunchServer.json) Bespoke exploit · alerting SΣP [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token Bespoke actions · alerting DSΣPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] .NET build (dotnet/MSBuild) spawns git config to harvest user.email Bespoke actions · hunting DSΣPDDCS [LLM] Python interpreter reading SSH/GPG private keys (jeIlyfish key theft) Bespoke actions · hunting DSΣPCS

Articles citing this technique (13)