{"id":"T1003.007","name":"Proc Filesystem","url":"https://attack.mitre.org/techniques/T1003/007","tactics":["credential-access"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0593","stix_id":"x-mitre-detection-strategy--dc017318-98a3-450b-b903-fe1e7d988197","name":"Detecting OS Credential Dumping via /proc Filesystem Access on Linux","url":"https://attack.mitre.org/detectionstrategies/DET0593","analytics":[{"id":"AN1631","stix_id":"x-mitre-analytic--98b71f96-ae0a-47b4-bec2-156cb6e5bfcb","name":"Analytic 1631","description":"Monitoring adversary access to sensitive process memory via the /proc filesystem to extract credential material, often involving multi-step access to /proc/[pid]/mem or /proc/[pid]/maps combined with privilege escalation or credential scraping binaries.","url":"https://attack.mitre.org/detectionstrategies/DET0593#AN1631","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"open, read","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"ptrace or process_vm_readv","data_component":"DC0035","data_component_name":"Process Access","log_source_slug":"auditd-syscall"},{"name":"linux:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"AccessedFilePath","description":"Monitored paths such as /proc/[pid]/mem or /proc/[pid]/maps may need to be scoped based on environment"},{"field":"ProcessName","description":"Command-line or binary names associated with credential scraping tools may vary"},{"field":"UserContext","description":"Elevated user or unexpected user context accessing other process memory may indicate malicious activity"},{"field":"TimeWindow","description":"Correlating memory access with process creation or ptrace activity within a specific time range"}],"live":true,"detection_strategies":["DET0593"],"techniques":["T1003.007"]}],"live":true,"version":"1.0","techniques":["T1003.007"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}