Suspicious Grep of Sensitive Contents for Credential Access

Rule Info

Name
Suspicious Grep of Sensitive Contents for Credential Access
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the use of grep to search for sensitive credentials and cryptocurrency wallet mnemonics. This behaviour may indicate an adversary trying to to locate sensitive credentials contained in environment variable files, private keys, certificates, wallet files, or other files that may contain secrets which could be used for credential access or further compromise.
Date
2026-08-07 00:00:00
Modified
None
Id
26e2a7ac-7de6-4b0c-9608-19a2984734fd
Tags
attack.credential-access attack.t1552.001
Type
Nextron Sigma feed only (private)

Rule History