daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

credential-hunting.md (30530B)


      1 ---
      2 title: "Credential Hunting"
      3 description: "grep -r password /path 2>/dev/null"
      4 category: enumeration
      5 tags: ["enumeration"]
      6 tools: []
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Enumeration/Credential Hunting.md"
     10 ---
     11 # Basic recursive search (case-insensitive, whole word, suppress errors)
     12 grep -r password /path 2>/dev/null
     13 
     14 # Best practice: case-insensitive, line numbers, skip binaries, with color
     15 grep -rnIi --color=auto 'password' /etc 2>/dev/null
     16 
     17 # Multiple patterns (OR logic)
     18 grep -rnIi -E 'password|api_key|secret|token' /var/www 2>/dev/null
     19 ```
     20 
     21 ### Options and Flags
     22 
     23 1. **-r** — Recursive search through directories
     24 2. **-i** — Case-insensitive matching
     25 3. **-n** — Show line numbers in output
     26 4. **-I** — Skip binary files (prevents "Binary file matches" messages)
     27 5. **-w** — Match whole word only (prevents false positives like "password_protected")
     28 6. **-l** — List filenames only (no content; faster for large result sets)
     29 7. **-H** — Always print filename with matches (default for multiple files)
     30 8. **-o** — Print only matching part of line (useful for extracting values)
     31 9. **-E** — Extended regex (enables `|` for OR, `+`, `?`)
     32 10. **--color=auto** — Highlight matches (always use this)
     33 11. **--include='*.ext'** — Search only specific file types
     34 12. **--exclude-dir='dir'** — Skip directories (e.g., node_modules, .git)
     35 13. **2>/dev/null** — Suppress permission denied errors
     36 
     37 ### Practical Examples
     38 
     39 ```bash
     40 # Search all config files for password strings
     41 grep -rnIi --include='*.conf' --include='*.config' --include='*.cnf' 'password' /etc 2>/dev/null
     42 
     43 # Find database credentials in web apps
     44 grep -rnIi -E 'DB_PASS|DATABASE_PASSWORD|dbpass' /var/www 2>/dev/null
     45 
     46 # Extract values after "password=" pattern
     47 grep -roIi 'password=' /opt | cut -d= -f2
     48 
     49 # Search with multiple keywords across targeted directories
     50 grep -rnIi -E 'pass=|pwd=|api_key=|secret=' /etc /opt /var/www /home 2>/dev/null | tee creds.txt
     51 
     52 # Find SSH private keys
     53 grep -rnI 'BEGIN.*PRIVATE KEY' /home /root 2>/dev/null
     54 
     55 # Exclude irrelevant directories to reduce noise
     56 grep -rnIi --exclude-dir={proc,sys,dev,run,boot} 'password' / 2>/dev/null
     57 ```
     58 
     59 ### Output Interpretation
     60 
     61 **Format:** `filename:line_number:matching_line`
     62 
     63 **Look for:**
     64 1. Plaintext credentials
     65 2. Connection strings
     66 3. API keys
     67 4. Environment variable assignments
     68 
     69 **False positives:** Documentation, comments, variable names without values
     70 
     71 ### OPSEC and Detection Notes
     72 
     73 1. **HIGH NOISE**: Recursive grep from `/` generates massive I/O and CPU load; detectable by performance monitoring
     74 2. **LOGGED**: [auditd](https://linux-audit.com/) file watches on `/etc/shadow`, `/etc/passwd`, `~/.ssh/*` will log read attempts to `/var/log/audit/audit.log`
     75 3. **EDR DETECTION**: Rapid sequential file reads across multiple sensitive directories trigger anomaly alerts
     76 4. **MITIGATION**: Use targeted directory searches (`/var/www`, `/opt`, `/home/user`) instead of whole filesystem; use `--exclude-dir` liberally
     77 5. Permission denied errors flood terminal without `2>/dev/null`; also hides potential targets
     78 
     79 ### Common Errors
     80 
     81 1. `Binary file (standard input) matches` — File contains null bytes or UTF-16 encoding; use `-I` to skip or `-a` to force text treatment
     82 2. Hangs with no output — grep waiting for stdin when no file argument given; use Ctrl+D to exit
     83 3. `grep: memory exhausted` — Pattern too complex or file too large; narrow search scope or use simpler regex
     84 4. No matches found — Check case sensitivity (`-i`), file permissions, [SELinux](https://www.redhat.com/en/topics/linux/what-is-selinux) denials (`ls -Z`, `sestatus`)
     85 5. Shell glob expansion — Quote patterns with wildcards: `'pass*'` not `pass*`
     86 
     87 ### Version and Platform Notes
     88 
     89 1. [GNU grep](https://www.gnu.org/software/grep/) (Linux default): supports lazy matching, `-P` for Perl regex
     90 2. [BSD grep](https://www.freebsd.org/cgi/man.cgi?query=grep) (macOS default): limited regex features, no lazy matching
     91 3. GNU grep 3.0+ includes performance optimizations for large files
     92 
     93 ---
     94 
     95 ## Phase 1: Fast Filename Enumeration
     96 
     97 **Purpose:** Quickly locate files with password-related names before content searching
     98 
     99 **Prerequisites:** Standard user access; [locate](https://man7.org/linux/man-pages/man1/locate.1.html) database (`updatedb`) ideally current
    100 
    101 ### Core Commands
    102 
    103 ```bash
    104 # Fastest: locate database search (requires updated database)
    105 locate -i password
    106 locate -i 'pass'
    107 locate -r '\.conf$'
    108 
    109 # Filename-only find (case-insensitive)
    110 find / -iname '*password*' 2>/dev/null
    111 find / -iname '*pass*' -o -iname '*pwd*' -o -iname '*credential*' 2>/dev/null
    112 ```
    113 
    114 ### Options and Flags
    115 
    116 1. **locate -i** — Case-insensitive filename search
    117 2. **locate -r** — Regex pattern matching
    118 3. **find -iname** — Case-insensitive name pattern
    119 4. **-o** — OR operator for multiple find conditions
    120 5. **updatedb** — Refresh locate database (requires root; runs daily via cron)
    121 
    122 ### Practical Examples
    123 
    124 ```bash
    125 # Search for password-related filenames (super fast)
    126 locate -i password | grep -v 'lib\|share\|fonts\|doc'
    127 locate -i pwd | grep -v 'lib\|share\|fonts\|doc'
    128 
    129 # Find config files by name
    130 locate '.conf' | grep -i 'password\|mysql\|db\|api'
    131 
    132 # Find with name patterns
    133 find /var/www /opt /home -type f \( -iname '*pass*' -o -iname '*secret*' -o -iname '*.pem' \) 2>/dev/null
    134 
    135 # Find files modified in last 7 days
    136 find /var/www /tmp -type f -mtime -7 -iname '*config*' 2>/dev/null
    137 ```
    138 
    139 ### Output Interpretation
    140 
    141 1. Full file paths; manually inspect high-value targets (`.conf`, `.cnf`, `.sh`, `.env`, `.bak`)
    142 2. **Prioritize:** `/etc`, `/var/www`, `/opt`, `/home`, `/root/.ssh`, `/tmp`
    143 
    144 ### OPSEC and Detection Notes
    145 
    146 1. **LOW NOISE**: locate reads pre-built database (no filesystem traversal; very fast)
    147 2. **MODERATE NOISE**: `find /` traverses filesystem; detectable via I/O monitoring
    148 3. Target specific directories to minimize footprint: `find /var/www /opt /home` not `find /`
    149 
    150 ### Common Errors
    151 
    152 1. `locate: can not stat` — Database stale; run `updatedb` (requires root) or use find
    153 2. `find: permission denied` — Normal for non-root user; redirect stderr with `2>/dev/null`
    154 
    155 ### Version and Platform Notes
    156 
    157 1. locate database location varies: `/var/lib/mlocate/mlocate.db` (Debian/Ubuntu), `/var/db/locate.database` (BSD)
    158 2. updatedb runs daily via `/etc/cron.daily/mlocate` on modern Linux
    159 
    160 ---
    161 
    162 ## Phase 2: Targeted File Type Enumeration
    163 
    164 **Purpose:** Enumerate high-value file types (configs, DBs, scripts, backups) before content search
    165 
    166 **Prerequisites:** Standard user access; bash shell
    167 
    168 ### Core Commands
    169 
    170 ```bash
    171 # Find all config files
    172 find /etc /opt /var/www -type f \( -name '*.conf' -o -name '*.config' -o -name '*.cnf' \) 2>/dev/null
    173 
    174 # Find database files
    175 find / -type f \( -name '*.sql' -o -name '*.db' -o -name '*.sqlite*' \) 2>/dev/null
    176 
    177 # Find scripts and environment files
    178 find /var/www /opt /home -type f \( -name '*.sh' -o -name '*.env' -o -name '.env' \) 2>/dev/null
    179 ```
    180 
    181 ### Options and Flags
    182 
    183 1. **find -type f** — Regular files only (excludes directories, links)
    184 2. **-name 'pattern'** — Case-sensitive name matching
    185 3. **-iname 'pattern'** — Case-insensitive name matching
    186 4. **-o** — OR operator for multiple name conditions
    187 5. **\( \)** — Group multiple conditions
    188 
    189 ### Practical Examples
    190 
    191 ```bash
    192 # Configuration file loop (clean output)
    193 for ext in conf config cnf; do 
    194   echo -e "\n=== Files with .$ext extension ==="; 
    195   find /etc /opt /var/www -name "*.$ext" 2>/dev/null | grep -v 'lib\|fonts\|share\|doc'; 
    196 done
    197 
    198 # Database file loop with filtering
    199 for ext in sql db sqlite sqlite3; do 
    200   echo -e "\n=== Files with .$ext extension ==="; 
    201   find / -name "*.$ext" 2>/dev/null | grep -v 'lib\|share\|man\|doc'; 
    202 done
    203 
    204 # Backup and archive files (high-value targets)
    205 find / -type f \( -name '*.bak' -o -name '*.backup' -o -name '*.old' -o -name '*~' \) 2>/dev/null | head -50
    206 
    207 # SSH keys and certificates
    208 find / -type f \( -name 'id_rsa' -o -name 'id_dsa' -o -name 'id_ed25519' -o -name '*.pem' -o -name '*.key' \) 2>/dev/null
    209 
    210 # World-readable files (permission misconfiguration)
    211 find / -type f -perm -004 -ls 2>/dev/null | grep -v 'proc\|sys\|usr/share'
    212 
    213 # SUID/SGID binaries (potential privilege escalation)
    214 find / -type f \( -perm -4000 -o -perm -2000 \) -ls 2>/dev/null
    215 ```
    216 
    217 ### Output Interpretation
    218 
    219 1. Paths to files; next step is content search with grep
    220 2. Prioritize small files (`-size -100k`) for faster manual inspection
    221 3. Large `.sql` or `.db` files may require [strings](https://man7.org/linux/man-pages/man1/strings.1.html) or specialized tools
    222 
    223 ### OPSEC and Detection Notes
    224 
    225 1. **MODERATE NOISE**: Filesystem traversal generates I/O; EDR may flag rapid enumeration
    226 2. Target specific directories first (`/var/www`, `/opt`, `/etc`, `/home`) before whole filesystem
    227 3. Exclude noisy system paths with `grep -v` to reduce output volume
    228 
    229 ### Common Errors
    230 
    231 1. `find: missing argument to '-name'` — Quote patterns: `-name '*.conf'` not `-name *.conf`
    232 2. Too many results — Add size filters (`-size -10M`), time filters (`-mtime -30`), or path restrictions
    233 
    234 ---
    235 
    236 ## Phase 3: Content Search in Targeted Files
    237 
    238 **Purpose:** Search file contents for credential patterns after identifying target files
    239 
    240 **Prerequisites:** List of target files (from Phase 2); standard user or root access
    241 
    242 ### Core Commands
    243 
    244 ```bash
    245 # Pipe find results to grep with xargs (handles spaces)
    246 find /etc /opt /var/www -type f -name '*.conf' -print0 | xargs -0 grep -nIi 'password' 2>/dev/null
    247 
    248 # Execute grep on each find result
    249 find /var/www -type f \( -name '*.conf' -o -name '*.php' -o -name '*.env' \) -exec grep -HnIi 'password\|api_key' {} \; 2>/dev/null
    250 ```
    251 
    252 ### Options and Flags
    253 
    254 1. **find -print0** — Null-separated output (handles filenames with spaces)
    255 2. **xargs -0** — Read null-separated input
    256 3. **find -exec grep {} \;** — Execute grep on each file individually
    257 4. **grep -H** — Always show filename (critical for multi-file searches)
    258 
    259 ### Practical Examples
    260 
    261 ```bash
    262 # Search config files for database credentials
    263 find /etc /opt -name '*.conf' -exec grep -HnIi -E 'password|user|host|dbname' {} \; 2>/dev/null
    264 
    265 # Search web app files for API keys
    266 find /var/www -type f \( -name '*.php' -o -name '*.py' -o -name '*.js' -o -name '.env' \) -print0 | \
    267   xargs -0 grep -nIi -E 'api[_-]?key|secret|token|auth' 2>/dev/null
    268 
    269 # Search scripts for embedded credentials
    270 find /home /opt -name '*.sh' -exec grep -HnIi -E 'export.*PASS|PASSWORD=' {} \; 2>/dev/null
    271 
    272 # Combined file type + content search one-liner
    273 find /etc /opt /var/www -type f \( -name '*.conf' -o -name '*.config' -o -name '*.cnf' \) \
    274   -exec grep -Hn 'password\|pass=' {} \; 2>/dev/null | tee config-creds.txt
    275 
    276 # Search only recently modified files (last 30 days)
    277 find /var/www -type f -mtime -30 -name '*.conf' -print0 | \
    278   xargs -0 grep -nIi 'password' 2>/dev/null
    279 ```
    280 
    281 ### Output Interpretation
    282 
    283 **Format:** `filename:line_number:matching_line`
    284 
    285 1. Extract values: pipe to `cut`, `awk`, or `sed` for parsing
    286 2. Context: use `grep -A 2 -B 2` to see surrounding lines
    287 
    288 ### OPSEC and Detection Notes
    289 
    290 1. **HIGH NOISE**: Reading many files rapidly triggers I/O alerts and auditd logging
    291 2. Target smallest file set possible; use Phase 2 filtering aggressively
    292 3. Sensitive file access (e.g., `/etc/shadow`, `~/.ssh/id_rsa`) logged by auditd to `/var/log/audit/audit.log`
    293 
    294 ### Common Errors
    295 
    296 1. `xargs: argument line too long` — Large result sets exceed buffer; use `find -exec` instead
    297 2. Binary files slow search — Always use `-I` flag with grep to skip binaries
    298 3. No output despite known credentials — Check file encoding (`file filename`), SELinux contexts
    299 
    300 ---
    301 
    302 ## Phase 4: History and Environment Inspection
    303 
    304 **Purpose:** Check command history, environment variables, and process memory for credentials
    305 
    306 **Prerequisites:** Standard user or root shell access
    307 
    308 ### Core Commands
    309 
    310 ```bash
    311 # Check command history files
    312 cat ~/.bash_history ~/.zsh_history 2>/dev/null | grep -i 'pass\|user\|key\|secret'
    313 
    314 # Check current environment variables
    315 env | grep -i 'pass\|key\|secret\|token\|api'
    316 
    317 # Check process command lines
    318 ps auxww | grep -E 'mysql|psql|ssh|ftp' | grep -v grep
    319 ```
    320 
    321 ### Practical Examples
    322 
    323 ```bash
    324 # History files across all users (requires root)
    325 find /home /root -type f \( -name '.bash_history' -o -name '.zsh_history' -o -name '.mysql_history' \) \
    326   -exec grep -HnIi -E 'password|pass=|--password' {} \; 2>/dev/null
    327 
    328 # Additional history files
    329 cat ~/.lesshst ~/.viminfo ~/.python_history 2>/dev/null | grep -i 'pass'
    330 
    331 # Environment variables from specific process
    332 cat /proc/[PID]/environ | tr '\0' '\n' | grep -i 'pass\|key'
    333 
    334 # All process environments (requires root)
    335 for pid in $(ls /proc | grep '^[0-9]'); do 
    336   echo "=== PID $pid ==="; 
    337   cat /proc/$pid/environ 2>/dev/null | tr '\0' '\n' | grep -iE 'pass|key|secret'; 
    338 done
    339 
    340 # Database connection strings in process memory (requires root)
    341 ps aux | grep -E 'mysql|postgres' | awk '{print $2}' | \
    342   xargs -I {} sh -c 'strings /proc/{}/environ 2>/dev/null | grep -i password'
    343 
    344 # Check systemd service files for credentials
    345 grep -rnIi 'Environment=' /etc/systemd/system /usr/lib/systemd/system 2>/dev/null | \
    346   grep -iE 'pass|key|secret'
    347 ```
    348 
    349 ### Output Interpretation
    350 
    351 1. History files may contain credentials passed as CLI arguments
    352 2. Environment variables often store DB passwords, API keys, tokens
    353 3. Process command lines expose credentials in `--password=value` style arguments
    354 4. `/proc/[pid]/environ` contains environment at process launch time
    355 
    356 ### OPSEC and Detection Notes
    357 
    358 1. **LOW NOISE**: Reading history files and env variables minimal impact
    359 2. **MODERATE NOISE**: Iterating over all `/proc/[pid]/environ` may trigger EDR alerts
    360 3. auditd may log access to specific users' history files if watched
    361 
    362 ### Common Errors
    363 
    364 1. `/proc/[pid]/environ` access denied — Processes owned by other users unreadable without root
    365 2. Empty output from `cat /proc/[pid]/environ` — Process exited or no environment variables
    366 3. History file not found — User using different shell or history disabled (`HISTFILE=`)
    367 
    368 ### Version and Platform Notes
    369 
    370 1. `/proc` filesystem standard on Linux; not available on BSD/macOS (use `ps e` instead)
    371 
    372 ---
    373 
    374 ## Phase 5: Log File Analysis
    375 
    376 **Purpose:** Search system and application logs for credentials, authentication events, and errors exposing secrets
    377 
    378 **Prerequisites:** Read access to `/var/log` (many logs require root)
    379 
    380 ### Core Commands
    381 
    382 ```bash
    383 # Search all log files for password strings
    384 grep -rnIi 'password' /var/log 2>/dev/null
    385 
    386 # Search compressed logs with zgrep
    387 zgrep -ai 'password\|credential\|secret' /var/log/*.gz 2>/dev/null
    388 
    389 # Loop through logs for authentication events
    390 for log in /var/log/*; do 
    391   grep -iE 'accepted|password|failure' "$log" 2>/dev/null && echo "=== $log ==="; 
    392 done
    393 ```
    394 
    395 ### Options and Flags
    396 
    397 1. **[zgrep](https://linux.die.net/man/1/zgrep)** — Search compressed files (`.gz`, `.bz2`)
    398 2. **zgrep -a** — Treat all files as text (avoids binary detection)
    399 3. Standard grep flags apply: `-i`, `-n`, `-E`, `-r`
    400 
    401 ### Practical Examples
    402 
    403 ```bash
    404 # SSH authentication logs
    405 grep -i 'accepted\|failed' /var/log/auth.log /var/log/secure 2>/dev/null | tail -50
    406 
    407 # Application error logs (may expose DB connection strings)
    408 grep -rnIi -E 'error.*password|exception.*credential' /var/log 2>/dev/null
    409 
    410 # Web server logs for API keys in URLs (bad practice but happens)
    411 grep -rE 'api_key=|token=' /var/log/apache2 /var/log/nginx 2>/dev/null | head -20
    412 
    413 # Database logs
    414 grep -rnIi 'password' /var/log/mysql /var/log/postgresql 2>/dev/null
    415 
    416 # Search compressed logs (older rotated logs)
    417 zgrep -aiE 'password=|api_key=|secret=' /var/log/*.gz /var/log/*/*.gz 2>/dev/null | less
    418 
    419 # Conditional log search (only print logs with matches)
    420 for logfile in $(ls /var/log/* 2>/dev/null); do 
    421   RESULT=$(grep -iE 'password|accepted|failure' "$logfile" 2>/dev/null); 
    422   if  $RESULT ; then 
    423     echo -e "\n=== $logfile ==="; 
    424     echo "$RESULT" | head -10; 
    425   fi; 
    426 done
    427 ```
    428 
    429 ### Output Interpretation
    430 
    431 1. **auth.log/secure:** successful/failed login attempts with usernames
    432 2. **Application logs:** stack traces may expose credentials in connection strings
    433 3. **Web logs:** API keys or tokens in GET parameters (insecure but common)
    434 4. **Look for:** timestamps, usernames, source IPs, credential exposure patterns
    435 
    436 ### OPSEC and Detection Notes
    437 
    438 1. **HIGH ALERT**: Access to `/var/log/auth.log`, `/var/log/secure`, `/var/log/audit/` triggers high-priority alerts
    439 2. auditd logs its own file watches to `/var/log/audit/audit.log` — reading this creates recursive log entry
    440 3. Legitimate sysadmins read logs frequently; timing and context matter for detection
    441 
    442 ### Common Errors
    443 
    444 1. `grep: /var/log/[file]: Permission denied` — Many logs require root; run as root or use `sudo`
    445 2. `zgrep: command not found` — Install gzip utils: `apt install gzip` or `yum install gzip`
    446 3. Binary log formats — [systemd journal](https://www.freedesktop.org/software/systemd/man/systemd-journald.service.html) uses binary format; use `journalctl` instead of grep
    447 
    448 ### Version and Platform Notes
    449 
    450 1. Log paths vary: `/var/log/auth.log` (Debian/Ubuntu), `/var/log/secure` (RHEL/CentOS)
    451 2. systemd systems: use `journalctl -xe | grep -i password` for systemd journal
    452 
    453 ---
    454 
    455 ## find File Discovery and Filtering
    456 
    457 **Purpose:** Locate files by name, type, size, permissions, modification time before content search
    458 
    459 **Prerequisites:** Standard user access; [GNU findutils](https://www.gnu.org/software/findutils/)
    460 
    461 ### Core Commands
    462 
    463 ```bash
    464 # Basic recursive file search
    465 find /path -type f -name 'pattern' 2>/dev/null
    466 
    467 # Search with multiple name patterns (OR logic)
    468 find / -type f \( -name '*.conf' -o -name '*.config' \) 2>/dev/null
    469 
    470 # Permission-based search
    471 find / -type f -perm -004 2>/dev/null
    472 ```
    473 
    474 ### Options and Flags
    475 
    476 1. **-type f** — Regular files only
    477 2. **-type d** — Directories only
    478 3. **-name 'pattern'** — Case-sensitive name match (shell wildcards: `*`, `?`)
    479 4. **-iname 'pattern'** — Case-insensitive name match
    480 5. **-perm -mode** — Files with at least these permissions set
    481 6. **-perm /mode** — Files with any of these permissions set
    482 7. **-user username** — Files owned by user
    483 8. **-group groupname** — Files owned by group
    484 9. **-size +100M** — Files larger than 100MB (`+` greater, `-` smaller, no prefix exact)
    485 10. **-mtime -7** — Modified in last 7 days (`-` within, `+` older than)
    486 11. **-atime** — Last access time
    487 12. **-ctime** — Last status change time
    488 13. **\( \)** — Group multiple expressions
    489 14. **-o** — OR operator
    490 15. **! or -not** — Negation
    491 
    492 ### Practical Examples
    493 
    494 ```bash
    495 # World-writable files (security risk)
    496 find / -type f -perm -002 2>/dev/null
    497 
    498 # SUID binaries (privilege escalation vectors)
    499 find / -type f -perm -4000 -ls 2>/dev/null
    500 
    501 # Files owned by www-data user
    502 find /var/www -user www-data -type f 2>/dev/null
    503 
    504 # Large files (potential DB dumps)
    505 find / -type f -size +50M -size -500M 2>/dev/null
    506 
    507 # Recently modified config files (may contain fresh creds)
    508 find /etc -type f -name '*.conf' -mtime -7 2>/dev/null
    509 
    510 # SSH keys across all user home directories
    511 find /home /root -type f \( -name 'id_rsa' -o -name 'id_dsa' -o -name 'id_ed25519' \) 2>/dev/null
    512 
    513 # Writable directories (potential persistence locations)
    514 find / -type d -perm -002 ! -path '/proc/*' ! -path '/sys/*' 2>/dev/null
    515 
    516 # Files with no user ownership (orphaned files)
    517 find / -nouser -ls 2>/dev/null
    518 ```
    519 
    520 ### Output Interpretation
    521 
    522 1. Default: full path to matching files
    523 2. Use `-ls` for detailed output (permissions, size, owner, timestamp)
    524 3. Pipe results to grep, xargs, or `-exec` for further processing
    525 
    526 ### OPSEC and Detection Notes
    527 
    528 1. **MODERATE-HIGH NOISE**: Full filesystem traversal from `/` generates significant I/O
    529 2. Target specific directories to reduce footprint
    530 3. SUID/permission enumeration is standard attacker behavior; may trigger alerts
    531 
    532 ### Common Errors
    533 
    534 1. `find: missing argument to '-name'` — Quote wildcards: `-name '*.conf'`
    535 2. `find: invalid argument '-perm 777'` — Use octal: `-perm 0777` or symbolic: `-perm -u=rwx,g=rwx,o=rwx`
    536 3. Parentheses syntax error — Escape with backslash: `\(` `\)` or quote: `'(' ')'`
    537 4. Slow search — Exclude large directories: `! -path '/proc/*' ! -path '/sys/*'`
    538 
    539 ### Version and Platform Notes
    540 
    541 1. GNU find (Linux): supports `-printf`, `-regex`, extended options
    542 2. BSD find (macOS): limited features; use `-print0` and `xargs -0` for portability
    543 
    544 ---
    545 
    546 ## strings Binary File Extraction
    547 
    548 **Purpose:** Extract printable ASCII strings from binary files (executables, compiled code, memory dumps)
    549 
    550 **Prerequisites:** [GNU binutils](https://www.gnu.org/software/binutils/) installed (standard on Linux)
    551 
    552 ### Core Commands
    553 
    554 ```bash
    555 # Extract printable strings from binary
    556 strings /path/to/binary
    557 
    558 # Set minimum string length (default 4)
    559 strings -n 8 /path/to/binary
    560 
    561 # Search extracted strings for patterns
    562 strings /path/to/binary | grep -i 'password\|api\|key'
    563 ```
    564 
    565 ### Options and Flags
    566 
    567 1. **-n [num]** — Minimum string length (default 4; increase to reduce noise)
    568 2. **-a** — Scan entire file (default scans only initialized/loaded sections)
    569 3. **-t [format]** — Print offset of each string (`o` octal, `x` hex, `d` decimal)
    570 4. **-e [encoding]** — Character encoding (`s` 7-bit, `S` 8-bit, `b` 16-bit big-endian, `l` 16-bit little-endian)
    571 
    572 ### Practical Examples
    573 
    574 ```bash
    575 # Extract all strings and search for credentials
    576 strings /usr/local/bin/app | grep -iE 'password|user|api_key|secret'
    577 
    578 # Extract longer strings to reduce noise
    579 strings -n 10 /bin/suspicious | less
    580 
    581 # Extract strings with hex offsets
    582 strings -t x /path/to/binary | grep -i 'config'
    583 
    584 # Extract from memory dump or core dump
    585 strings /proc/[PID]/mem 2>/dev/null | grep -i 'pass'
    586 
    587 # Extract from all binaries in directory
    588 find /usr/local/bin -type f -executable -exec sh -c 'echo "=== {} ==="; strings {} | grep -i password' \; 2>/dev/null
    589 
    590 # Extract from libraries
    591 strings /usr/lib/*.so | grep -iE 'password|api_key' | sort -u
    592 ```
    593 
    594 ### Output Interpretation
    595 
    596 1. Raw printable strings; includes code, data, error messages, hardcoded credentials
    597 2. High noise-to-signal ratio; use grep filters and increase `-n` value
    598 3. **Look for:** connection strings, API endpoints, embedded credentials, license keys
    599 
    600 ### OPSEC and Detection Notes
    601 
    602 1. **LOW NOISE**: strings reads files like cat; minimal detection footprint
    603 2. Extracting strings from `/proc/[pid]/mem` requires same user or root; may log access
    604 
    605 ### Common Errors
    606 
    607 1. `strings: [file]: file format not recognized` — File truly not a binary; use `file` to verify
    608 2. Excessive output — Increase minimum length: `-n 8` or `-n 12`
    609 3. Permission denied on `/proc/[pid]/mem` — Requires root or process owner
    610 
    611 ### Version and Platform Notes
    612 
    613 1. GNU strings (Linux standard): supports all encodings and formats
    614 2. BSD strings (macOS): limited encoding support
    615 
    616 ---
    617 
    618 ## Parsing and Filtering Output (awk, sed, cut)
    619 
    620 **Purpose:** Extract and format specific fields from grep/find results
    621 
    622 **Prerequisites:** Standard Linux shell (bash/sh)
    623 
    624 ### Core Commands
    625 
    626 ```bash
    627 # awk: split by delimiter and print fields
    628 grep 'password=' file.conf | awk -F= '{print $2}'
    629 
    630 # cut: extract column by delimiter
    631 grep 'user:' file | cut -d: -f2
    632 
    633 # sed: regex extraction
    634 sed -n 's/.*password=\([^&]*\).*/\1/p' file
    635 ```
    636 
    637 ### Options and Flags
    638 
    639 1. **awk -F[char]** — Field separator (default whitespace)
    640 2. **awk {print $N}** — Print field N (1-indexed; `$0` entire line)
    641 3. **cut -d[char]** — Delimiter character
    642 4. **cut -f[N]** — Field number(s) to extract
    643 5. **sed -n** — Suppress default output (only print explicit `p` commands)
    644 6. **sed s/pattern/replacement/** — Substitute (regex)
    645 
    646 ### Practical Examples
    647 
    648 ```bash
    649 # Extract passwords from "password=value" format
    650 grep -ri 'password=' /etc | awk -F= '{print $2}'
    651 
    652 # Extract usernames from /etc/passwd (field 1, delimiter :)
    653 cut -d: -f1 /etc/passwd
    654 
    655 # Extract usernames and home directories
    656 awk -F: '{print $1 " -> " $6}' /etc/passwd
    657 
    658 # Extract database credentials from config
    659 grep -E 'user|password|host' db.conf | awk -F= '{print $1 ": " $2}'
    660 
    661 # Extract API keys from grep output (remove filename prefix)
    662 grep -rh 'api_key=' /var/www | cut -d= -f2 | sort -u
    663 
    664 # Extract values between quotes
    665 sed -n 's/.*password="\([^"]*\)".*/\1/p' config.php
    666 
    667 # Extract IP addresses from logs
    668 grep 'Failed password' /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn
    669 
    670 # Parse JSON-like output (basic)
    671 grep -o '"password":"[^"]*"' config.json | cut -d'"' -f4
    672 ```
    673 
    674 ### Output Interpretation
    675 
    676 1. Extracted fields only; ready for further processing or reporting
    677 2. Use `sort -u` to deduplicate, `sort | uniq -c` to count occurrences
    678 
    679 ### OPSEC and Detection Notes
    680 
    681 **ZERO IMPACT**: awk/sed/cut operate on stdin/files; no network or unusual syscalls
    682 
    683 ### Common Errors
    684 
    685 1. Wrong field number — Count fields carefully; awk is 1-indexed
    686 2. Delimiter not matched — Verify with `head` first; ensure delimiter present
    687 3. sed regex not matching — Test pattern with simpler examples; escape special chars
    688 
    689 ### Version and Platform Notes
    690 
    691 1. POSIX-compliant awk/sed/cut work on all Linux/Unix
    692 2. [GNU awk (gawk)](https://www.gnu.org/software/gawk/) supports advanced features (multi-char separators, arrays)
    693 
    694 ---
    695 
    696 ## OPSEC and Detection Awareness
    697 
    698 **Purpose:** Understand what defensive tools log when searching for credentials
    699 
    700 **Prerequisites:** Awareness of target environment (auditd, EDR, SIEM presence)
    701 
    702 ### Core Detection Mechanisms
    703 
    704 1. **[auditd](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/chap-system_auditing)** — File access monitoring; logs to `/var/log/audit/audit.log`
    705 2. **EDR agents** — Behavioral detection; anomaly scoring for file enumeration patterns
    706 3. **syslog** — General system logging; may capture bash history or command execution
    707 4. **Process accounting (psacct)** — Logs executed commands
    708 
    709 ### Key Indicators of Compromise (IOCs) Generated
    710 
    711 1. Recursive grep from `/` — High I/O load, CPU spike, massive file read count
    712 2. Access to `/etc/shadow`, `/etc/passwd`, `~/.ssh/id_rsa` — High-priority alerts
    713 3. Rapid sequential file reads across multiple directories — Anomaly detection trigger
    714 4. Large result sets piped to output files — Unusual data exfiltration patterns
    715 
    716 ### Detection Check Commands
    717 
    718 ```bash
    719 # Check if auditd is running
    720 systemctl status auditd
    721 ps aux | grep auditd
    722 
    723 # Check existing audit watches (requires root)
    724 auditctl -l
    725 
    726 # Search audit logs for your own activity (requires root)
    727 ausearch --file /etc/shadow --interpret
    728 ausearch -k password-access -ts recent
    729 
    730 # Check for file watches on sensitive files
    731 auditctl -l | grep -E 'shadow|passwd|ssh'
    732 
    733 # Generate audit summary report (requires root)
    734 aureport -f | tail -50
    735 aureport -u | tail -20
    736 
    737 # Check if EDR/monitoring agent present
    738 ps aux | grep -iE 'falcon|crowdstrike|carbon|defender|sentinel|tanium'
    739 
    740 # Check SELinux status (may block file access)
    741 sestatus
    742 ls -Z /etc/shadow
    743 ```
    744 
    745 ### Output Interpretation
    746 
    747 1. auditd file watches indicate monitored paths
    748 2. EDR processes indicate behavioral monitoring active
    749 3. SELinux enforcing mode may silently block reads
    750 
    751 ### OPSEC Recommendations
    752 
    753 1. **Target scope aggressively**: Search `/var/www`, `/opt`, specific user homes instead of `/`
    754 2. **Exclude system directories**: Use `--exclude-dir={proc,sys,dev,run,usr/share}` with grep
    755 3. **Small result sets**: Use `-l` (filenames only) until target narrowed
    756 4. **Blend with normal activity**: Sysadmins search logs frequently; timing and context matter
    757 5. **Avoid high-value files initially**: Test with lower-risk directories first
    758 6. **Throttle I/O**: Add `sleep` between operations or use `nice`/`ionice` to reduce resource impact
    759 
    760 ### Common Detection Artifacts
    761 
    762 1. **`/var/log/audit/audit.log`** — File access records: `type=PATH msg=audit(...): item=0 name="/etc/shadow"`
    763 2. **Bash history** — Commands logged to `~/.bash_history` (disable: `unset HISTFILE`)
    764 3. **Process command line** — Visible in `ps auxww` output while running
    765 4. **Network anomaly** — Large internal file reads may correlate with exfil attempts
    766 
    767 ### Mitigation Against Detection
    768 
    769 1. **Disable history temporarily**: `unset HISTFILE` or `set +o history`
    770 2. **Clear history**: `history -c; rm ~/.bash_history` (obvious indicator if monitored)
    771 3. **Use absolute paths**: Avoid relative paths that expose working directory context
    772 4. **Redirect output carefully**: Large output files in `/tmp` or home directory may trigger alerts
    773 
    774 ### Version and Platform Notes
    775 
    776 1. auditd standard on RHEL/CentOS/Fedora; may not be enabled by default on Debian/Ubuntu
    777 2. systemd `journalctl` also logs command execution on systemd-based systems
    778 
    779 ---
    780 
    781 ## References
    782 
    783 1. [GNU grep Manual](https://www.gnu.org/software/grep/manual/grep.html)
    784 2. [grep Man Page - Linux.die.net](https://linux.die.net/man/1/grep)
    785 3. [locate Man Page](https://man7.org/linux/man-pages/man1/locate.1.html)
    786 4. [find Man Page](https://linux.die.net/man/1/find)
    787 5. [Linux Privilege Escalation Using Misconfigured File Permissions - Hacking Articles](https://www.hackingarticles.in/linux-privilege-escalation-using-misconfigured-file-permissions/)
    788 6. [xargs Man Page](https://man7.org/linux/man-pages/man1/xargs.1.html)
    789 7. [Linux find Command - Red Hat Sysadmin](https://www.redhat.com/sysadmin/linux-find-command)
    790 8. [Linux /proc Filesystem Documentation](https://www.kernel.org/doc/Documentation/filesystems/proc.txt)
    791 9. [ps Man Page](https://linux.die.net/man/1/ps)
    792 10. [Linux Log Files Location and Viewing Guide - nixCraft](https://www.cyberciti.biz/faq/linux-log-files-location-and-how-do-i-view-logs-files/)
    793 11. [journalctl Man Page](https://man7.org/linux/man-pages/man1/journalctl.1.html)
    794 12. [GNU find Manual](https://www.gnu.org/software/findutils/manual/html_mono/find.html)
    795 13. [strings Man Page](https://man7.org/linux/man-pages/man1/strings.1.html)
    796 14. [awk Man Page](https://man7.org/linux/man-pages/man1/awk.1p.html)
    797 15. [GNU sed Manual](https://www.gnu.org/software/sed/manual/sed.html)
    798 16. [Understanding Audit Log Files - Red Hat](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-understanding_audit_log_files)
    799 17. [Configuring and Auditing Linux Systems with auditd](https://linux-audit.com/configuring-and-auditing-linux-systems-with-auditd/)
    800 
    801 #Linux #PrivEsc #Enumeration #Credentials #grep #find #OPSEC #Logs #FileEnumeration #PasswordHunting