Harvesting developer and cloud secrets
cred_secret_file_harvest
Looks for SSH private keys, cloud CLI credentials, Kubernetes and Docker configuration, .netrc and package-manager tokens, and for credential-shaped environment variables. Only paths, sizes and digests are recorded — never any secret material.
What it needs before it will run
-
runs in --safeObservation only. It runs even in the inert mode, because it changes nothing and sends nothing.
Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.
ATT&CK techniques it exercises
| Technique | Name | Tactic | Across public reports |
|---|---|---|---|
| T1552.001 | Credentials In Files | Credential Access | coverage statistics |
| T1552.004 | Private Keys | Credential Access | coverage statistics |
| T1552.005 | Cloud Instance Metadata API | Credential Access | coverage statistics |
How often anything notices
Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.
Other credential access tests
| Test | What it does | Severity |
|---|---|---|
| LSASS minidump via a signed binary cred_lsass_minidump | Attempts the comsvcs.dll MiniDump technique through rundll32 — the most-alerted-on credential-dumping method there is — writing to the sandbox. Any du… | critical |
| Copying browser credential stores cred_browser_store_copy | Locates the browser password and cookie databases for Chrome, Edge, Brave and Firefox and copies them into the sandbox, which is exactly what an infos… | high |
| Reading DPAPI master keys cred_dpapi_masterkeys | Enumerates and copies the current user's DPAPI master key blobs, which are what an attacker needs to decrypt saved browser and Credential Manager secr… | high |
| Enumerating the macOS keychain cred_keychain_dump | Runs security(1) to list the login keychain's item metadata and to dump the keychain without the -d flag, so no secret is ever requested or printed. K… | high |
| Opening a handle to LSASS cred_lsass_handle | Opens a read handle to the LSASS process with PROCESS_VM_READ and closes it immediately without reading a single byte. Handle acquisition is the step … | high |
| Credential store access attempt credential_store_access | Attempts to copy the operating system's credential stores into the sandbox — the SAM, SYSTEM and SECURITY registry hives on Windows, /etc/shadow on Li… | high |
Catalogue generated from client 0.1.0. A test's behaviour can
change between releases; this page describes the version named here.