{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","url":"https://attack.mitre.org/techniques/T1003/008","tactics":["credential-access"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0446","stix_id":"x-mitre-detection-strategy--17c97a51-74c2-449c-bc95-cf6a7647fb83","name":"Credential Access via /etc/passwd and /etc/shadow Parsing","url":"https://attack.mitre.org/detectionstrategies/DET0446","analytics":[{"id":"AN1234","stix_id":"x-mitre-analytic--d6166e3d-2e29-4097-9fb4-c66ce0616897","name":"Analytic 1234","description":"Adversaries attempt to read sensitive files such as /etc/passwd and /etc/shadow for credential dumping. This may involve access to the files directly via command-line utilities (e.g., cat, less), creation of backup copies, or parsing through post-exploitation frameworks. Multi-event correlation includes elevated process execution, file access/read on sensitive paths, and anomalous read behaviors tied to non-root or unusual users.","url":"https://attack.mitre.org/detectionstrategies/DET0446#AN1234","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"exe","description":"Executable name used to access credentials (e.g., cat, cp, awk); can vary across environments"},{"field":"user","description":"User context under which the access occurs; typically root, but can be non-standard in attacks"},{"field":"PATH","description":"Target file paths (e.g., /etc/passwd, /etc/shadow); may vary in containerized or customized systems"},{"field":"TimeWindow","description":"Time correlation threshold for chaining access and execution events"}],"live":true,"detection_strategies":["DET0446"],"techniques":["T1003.008"]}],"live":true,"version":"1.0","techniques":["T1003.008"]}],"sigma_rules":[],"kev_cves":[{"cveID":"CVE-2024-24919","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}