{"id":"T1552.003","name":"Shell History","url":"https://attack.mitre.org/techniques/T1552/003","tactics":["credential-access"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0385","stix_id":"x-mitre-detection-strategy--653b555a-590f-40e4-9400-f14d0ed92252","name":"Detect Access and Parsing of .bash_history Files for Credential Harvesting","url":"https://attack.mitre.org/detectionstrategies/DET0385","analytics":[{"id":"AN1085","stix_id":"x-mitre-analytic--12be6c5f-213a-464f-b780-ac06f20ab763","name":"Analytic 1085","description":"A process outside of interactive shell context reads ~/.bash_history directly (e.g., using cat, less, grep), often shortly after privilege escalation or user switch (su/sudo). This may be followed by credential scanning in memory or file writes to new locations.","url":"https://attack.mitre.org/detectionstrategies/DET0385#AN1085","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open/read access to ~/.bash_history","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"cat|less|grep accessing .bash_history from a non-shell process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"auditd:SYSCALL","channel":"write or create file after .bash_history access","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"UserContext","description":"Filter by users with elevated privileges or service accounts"},{"field":"TimeWindow","description":"Correlate access to .bash_history within X seconds of user switch or privilege escalation"},{"field":"ProcessNamePatterns","description":"Add/remove CLI utilities used to read bash history"}],"live":true,"detection_strategies":["DET0385"],"techniques":["T1552.003"]},{"id":"AN1086","stix_id":"x-mitre-analytic--ead38dff-ee26-477d-be5a-69b52dc8bd50","name":"Analytic 1086","description":"A process or terminal command outside of standard shell utilities reads the user's .bash_history file. On macOS, unified logs or telemetry tools like EndpointSecurity (ESF) may observe file read APIs or terminal process lineage that shows non-user-initiated access.","url":"https://attack.mitre.org/detectionstrategies/DET0385#AN1086","platforms":["macOS"],"log_source_references":[{"name":"macos:endpointsecurity","channel":"open or read syscall to ~/.bash_history","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"macos-endpointsecurity"},{"name":"macos:unifiedlog","channel":"non-shell process tree accessing bash history","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ParentProcessCheck","description":"Scope access to .bash_history only if parent is not Terminal.app or bash/zsh"},{"field":"AccessFrequency","description":"Raise priority if .bash_history is accessed multiple times in short window"}],"live":true,"detection_strategies":["DET0385"],"techniques":["T1552.003"]}],"live":true,"version":"1.0","techniques":["T1552.003"]}],"sigma_rules":[{"id":"508a9374-ad52-4789-b568-fc358def2c65","title":"Suspicious History File Operations","author":"Mikhail Larin, oscd.community","status":"test","level":"medium","date":"2020-10-17","modified":"2021-11-27","description":"Detects commandline operations on shell history files","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.003/T1552.003.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.credential-access","attack.t1552.003"],"path":"rules/macos/process_creation/proc_creation_macos_susp_histfile_operations.yml","techniques":["T1552.003"],"cves":[]},{"id":"b094d9fb-b1ad-4650-9f1a-fb7be9f1d34b","title":"Cisco Show Commands Input","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-11","modified":"2023-01-04","description":"See what commands are being input into the device by other people, full credentials can be in the history","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.credential-access","attack.t1552.003"],"path":"rules/network/cisco/aaa/cisco_cli_input_capture.yml","techniques":["T1552.003"],"cves":[]},{"id":"eae8ce9f-bde9-47a6-8e79-f20d18419910","title":"Suspicious History File Operations - Linux","author":"Mikhail Larin, oscd.community","status":"test","level":"medium","date":"2020-10-17","modified":"2022-11-28","description":"Detects commandline operations on shell history files","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1552.003/T1552.003.md"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.credential-access","attack.t1552.003"],"path":"rules/linux/auditd/execve/lnx_auditd_susp_histfile_operations.yml","techniques":["T1552.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}