Esc
/etc/passwd and /etc/shadow - T1003.008
(ATT&CK® Technique)
Definition
Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a combination of /etc/passwd and /etc/shadow to store user account information including password hashes in /etc/shadow. By default, /etc/shadow is only readable by the root user.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.