{
  "technique_id": "T1552",
  "name": "Unsecured Credentials",
  "tactics": [
    "Credential Access"
  ],
  "platforms": [
    "Windows",
    "SaaS",
    "IaaS",
    "Linux",
    "macOS",
    "Containers",
    "Network Devices",
    "Office Suite",
    "Identity Provider"
  ],
  "summary": "Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or application-specific repositories (e.g. [Credentials in Registry](https://attack.mitre.org/techniques/T1552/002)), or other specialized files/artifacts (e.g...",
  "generated_by": "SOC Response Atlas by Basyrix"
}