Shell History

T1552.003

Sub-technique of T1552 Unsecured Credentials.View on attack.mitre.org

About this technique

Adversaries may search the command history on compromised systems for insecurely stored credentials.

On Linux and macOS systems, shells such as Bash and Zsh keep track of the commands users type on the command-line with the "history" utility. Once a user logs out, the history is flushed to the user's history file. For each user, this file resides at the same location: for example, `~/.bash_history` or `~/.zsh_history`. Typically, these files keeps track of the user's last 1000 commands.

On Windows, PowerShell has both a command history that is wiped after the session ends, and one that contains commands used in all sessions and is persistent. The default location for persistent history can be found in `%userprofile%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txt`, but command history can also be accessed with `Get-History`. Command Prompt (CMD) on Windows does not have persistent history.

Users often type usernames and passwords on the command-line as parameters to programs, which then get saved to this file when they log out. Adversaries can abuse this by looking through the file for potential credentials.

Detection rules4

Rules on DetectionCode tagged with T1552.003.

Sigma3

RuleLevelLog source
Cisco Show Commands Inputmediumcisco / NULL
Suspicious History File Operationsmediummacos / process_creation
Suspicious History File Operations - Linuxmediumlinux / NULL

Splunk1

RuleTypeRiskData source
Linux Shell History Access Via Command Line UtilityAnomalyNULLSysmon for Linux EventID 1

Groups0

None recorded.

Software2

Campaigns0

None recorded.

Procedure examples2

Software2

Used byProcedure example
MalwareKinsing

Kinsing has searched bash_history for credentials.

MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can target credentials in shell history on self-hosted runners.

References3

  1. External to DA, the OS X Way Open source
    Alex Rymdeko-Harvey, Steve Borosh. (2016, May 14). External to DA, the OS X Way. Retrieved September 12, 2024.
  2. Medium Open source
    Michael Koczwara. (2021, March 14). Windows privilege escalation via PowerShell History. Retrieved June 13, 2025.
  3. Microsoft about_History Open source
    Microsoft. (2024, January 19). about_History. Retrieved June 13, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.