Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Credential Access/ T1552

T1552Unsecured Credentials

T1552 — Unsecured Credentials is a MITRE ATT&CK technique in the Credential Access tactic. Clankerusecase tracks 17 detection use cases covering it and 6 threat-intel articles citing it.

Credential Access
View on the matrix → Filter Detection Library MITRE official spec ↗
17Use cases
6Articles
8Sub-techniques
1Tactic

Sub-techniques (8)

Use cases covering this technique (17)

GCP service-account key created Internal actions · alerting DD GitHub personal access token created Internal actions · alerting DD GitHub personal access token cloning many repositories Internal actions · alerting DD Splunk Sensitive Information Disclosure in DEBUG Logging Channels ESCU actions · hunting P Detect AWS Console Login by New User ESCU actions · hunting P O365 Email Suspicious Search Behavior ESCU actions · hunting P O365 SharePoint Suspicious Search Behavior ESCU actions · hunting P Windows LAPS Password Gathering Via PowerShell Script ESCU actions · hunting P Windows Post Exploitation Risk Behavior ESCU actions · alerting P Windows Unsecured Outlook Credentials Access In Registry ESCU actions · hunting P Cisco SNMP Community String Configuration Changes ESCU actions · hunting P Windows SharePoint Spinstall0 GET Request ESCU actions · alerting P [LLM] Cloud instance-metadata (IMDS 169.254.169.254) credential theft by interpreter/shell in pipeline pod Bespoke actions · alerting DSΣDDCS [LLM] Budibase server leaks datasource auth to first-seen host (undici + Authorization egress) Bespoke actions · hunting SP [LLM] Runner.Worker process memory scrape via /proc on self-hosted GitHub Actions runner Bespoke actions · alerting DSΣPDDCS [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) Bespoke actions · alerting DSΣPDDCS [LLM] Access to exposed Elector '/get-admin-users' credential-leaking API endpoint Bespoke exploit · alerting SΣP

Articles citing this technique (6)