Skip to content
← LibraryTechnique entry
T1552Credential Access

Unsecured Credentials

Credentials stored or transmitted insecurely (in source, env files, cloud metadata, password stores).

§ Where this technique fits

T1552 is catalogued under the Credential Access tactic of the offensive-security kill-chain. It appears in 18 approved dossiers in the registry, typically at step 4.4 on average.

Authoritative reference: attack.mitre.org/techniques/T1552/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Valid Accounts
    T1078 · Initial Access
    seen 5×
  2. 02
    Exfiltration Over C2 Channel
    T1041 · Exfiltration
    seen 3×
  3. 03
    S3 / Blob / GCS Mass Exfil
    C-S3-EXFIL · Collection
    seen 2×
  4. 04
    Account Discovery
    T1087 · Discovery
    seen 1×
  5. 05
    Modify Authentication Process
    T1556 · Credential Access
    seen 1×
  6. 06
    Password Spraying
    T1110.003 · Credential Access
    seen 1×
  7. 07
    Steal Web Session Cookie
    T1539 · Credential Access
    seen 1×