MITRE ATT&CK Technique
T1552.001Credentials In Files
- First Reported
- Sep 29, 2025
- Latest Reported
- Oct 7, 2026
Official Description
Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.
It is possible to extract passwords from backups or saved virtual machines through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003).(Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.(Citation: SRD GPP)
In cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files.(Citation: Unit 42 Hildegard Malware) They may also be found as parameters to deployment commands in container logs.(Citation: Unit 42 Unsecured Docker Daemons) In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.(Citation: Specter Ops - Cloud Credential Storage)
It is possible to extract passwords from backups or saved virtual machines through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003).(Citation: CG 2014) Passwords may also be obtained from Group Policy Preferences stored on the Windows Domain Controller.(Citation: SRD GPP)
In cloud and/or containerized environments, authenticated user and service account credentials are often stored in local configuration and credential files.(Citation: Unit 42 Hildegard Malware) They may also be found as parameters to deployment commands in container logs.(Citation: Unit 42 Unsecured Docker Daemons) In some cases, these files can be copied and reused on another machine or the contents can be read and then used to authenticate without needing to copy any files.(Citation: Specter Ops - Cloud Credential Storage)
- Tactics
- Credential Access
- Platforms
- Containers, IaaS, Linux, macOS, Windows
- Parent Technique
- T1552 · Unsecured Credentials
- MITRE Version
- 1.3
- Last Modified
- May 12, 2026
Reported Context (21)
- watchTowR researchers demonstrated that the flaw could expose plaintext application credentials in WEB-INF/classes/crowd.properties in Crowd-integrated Jira deployments. Hackers exploit critical unauthenticated Atlassian flaw after public PoC
- Azazel extracted credentials and tokens from GitLab CI/CD variables, repository history and cluster configuration files. CloudSEK Finds Gentlemen Ransomware Affiliate’s Exposed Servers and Stolen Data
- wp2s_crack.py requested exposed configuration, environment, repository, backup, and log files and extracted credential material from returned data. TIKTOUK Toolkit Collects WordPress, Email, and Cloud Credentials
- During an authorized security assessment, Kushal found a hardcoded database credential in an XML file and used it to access the database. Seven Layers of Cloud Defense: How Organizations Apply Defense in Depth
- Socket's static analysis found that sckit searches the user's home directory for credential files, including .npmrc, .vault-token and SSH secrets. Malicious MemTensor npm and PyPI Releases Target Developer Credentials
CVE (20)
Malware (21)
People (20)
Threat Actors (10)
MITRE ATT&CK (116)
Vendors (35)
Products (164)
Tools (95)
Industries (43)
Countries (36)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.