credential-hunting.md (30530B)
1 --- 2 title: "Credential Hunting" 3 description: "grep -r password /path 2>/dev/null" 4 category: enumeration 5 tags: ["enumeration"] 6 tools: [] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Enumeration/Credential Hunting.md" 10 --- 11 # Basic recursive search (case-insensitive, whole word, suppress errors) 12 grep -r password /path 2>/dev/null 13 14 # Best practice: case-insensitive, line numbers, skip binaries, with color 15 grep -rnIi --color=auto 'password' /etc 2>/dev/null 16 17 # Multiple patterns (OR logic) 18 grep -rnIi -E 'password|api_key|secret|token' /var/www 2>/dev/null 19 ``` 20 21 ### Options and Flags 22 23 1. **-r** — Recursive search through directories 24 2. **-i** — Case-insensitive matching 25 3. **-n** — Show line numbers in output 26 4. **-I** — Skip binary files (prevents "Binary file matches" messages) 27 5. **-w** — Match whole word only (prevents false positives like "password_protected") 28 6. **-l** — List filenames only (no content; faster for large result sets) 29 7. **-H** — Always print filename with matches (default for multiple files) 30 8. **-o** — Print only matching part of line (useful for extracting values) 31 9. **-E** — Extended regex (enables `|` for OR, `+`, `?`) 32 10. **--color=auto** — Highlight matches (always use this) 33 11. **--include='*.ext'** — Search only specific file types 34 12. **--exclude-dir='dir'** — Skip directories (e.g., node_modules, .git) 35 13. **2>/dev/null** — Suppress permission denied errors 36 37 ### Practical Examples 38 39 ```bash 40 # Search all config files for password strings 41 grep -rnIi --include='*.conf' --include='*.config' --include='*.cnf' 'password' /etc 2>/dev/null 42 43 # Find database credentials in web apps 44 grep -rnIi -E 'DB_PASS|DATABASE_PASSWORD|dbpass' /var/www 2>/dev/null 45 46 # Extract values after "password=" pattern 47 grep -roIi 'password=' /opt | cut -d= -f2 48 49 # Search with multiple keywords across targeted directories 50 grep -rnIi -E 'pass=|pwd=|api_key=|secret=' /etc /opt /var/www /home 2>/dev/null | tee creds.txt 51 52 # Find SSH private keys 53 grep -rnI 'BEGIN.*PRIVATE KEY' /home /root 2>/dev/null 54 55 # Exclude irrelevant directories to reduce noise 56 grep -rnIi --exclude-dir={proc,sys,dev,run,boot} 'password' / 2>/dev/null 57 ``` 58 59 ### Output Interpretation 60 61 **Format:** `filename:line_number:matching_line` 62 63 **Look for:** 64 1. Plaintext credentials 65 2. Connection strings 66 3. API keys 67 4. Environment variable assignments 68 69 **False positives:** Documentation, comments, variable names without values 70 71 ### OPSEC and Detection Notes 72 73 1. **HIGH NOISE**: Recursive grep from `/` generates massive I/O and CPU load; detectable by performance monitoring 74 2. **LOGGED**: [auditd](https://linux-audit.com/) file watches on `/etc/shadow`, `/etc/passwd`, `~/.ssh/*` will log read attempts to `/var/log/audit/audit.log` 75 3. **EDR DETECTION**: Rapid sequential file reads across multiple sensitive directories trigger anomaly alerts 76 4. **MITIGATION**: Use targeted directory searches (`/var/www`, `/opt`, `/home/user`) instead of whole filesystem; use `--exclude-dir` liberally 77 5. Permission denied errors flood terminal without `2>/dev/null`; also hides potential targets 78 79 ### Common Errors 80 81 1. `Binary file (standard input) matches` — File contains null bytes or UTF-16 encoding; use `-I` to skip or `-a` to force text treatment 82 2. Hangs with no output — grep waiting for stdin when no file argument given; use Ctrl+D to exit 83 3. `grep: memory exhausted` — Pattern too complex or file too large; narrow search scope or use simpler regex 84 4. No matches found — Check case sensitivity (`-i`), file permissions, [SELinux](https://www.redhat.com/en/topics/linux/what-is-selinux) denials (`ls -Z`, `sestatus`) 85 5. Shell glob expansion — Quote patterns with wildcards: `'pass*'` not `pass*` 86 87 ### Version and Platform Notes 88 89 1. [GNU grep](https://www.gnu.org/software/grep/) (Linux default): supports lazy matching, `-P` for Perl regex 90 2. [BSD grep](https://www.freebsd.org/cgi/man.cgi?query=grep) (macOS default): limited regex features, no lazy matching 91 3. GNU grep 3.0+ includes performance optimizations for large files 92 93 --- 94 95 ## Phase 1: Fast Filename Enumeration 96 97 **Purpose:** Quickly locate files with password-related names before content searching 98 99 **Prerequisites:** Standard user access; [locate](https://man7.org/linux/man-pages/man1/locate.1.html) database (`updatedb`) ideally current 100 101 ### Core Commands 102 103 ```bash 104 # Fastest: locate database search (requires updated database) 105 locate -i password 106 locate -i 'pass' 107 locate -r '\.conf$' 108 109 # Filename-only find (case-insensitive) 110 find / -iname '*password*' 2>/dev/null 111 find / -iname '*pass*' -o -iname '*pwd*' -o -iname '*credential*' 2>/dev/null 112 ``` 113 114 ### Options and Flags 115 116 1. **locate -i** — Case-insensitive filename search 117 2. **locate -r** — Regex pattern matching 118 3. **find -iname** — Case-insensitive name pattern 119 4. **-o** — OR operator for multiple find conditions 120 5. **updatedb** — Refresh locate database (requires root; runs daily via cron) 121 122 ### Practical Examples 123 124 ```bash 125 # Search for password-related filenames (super fast) 126 locate -i password | grep -v 'lib\|share\|fonts\|doc' 127 locate -i pwd | grep -v 'lib\|share\|fonts\|doc' 128 129 # Find config files by name 130 locate '.conf' | grep -i 'password\|mysql\|db\|api' 131 132 # Find with name patterns 133 find /var/www /opt /home -type f \( -iname '*pass*' -o -iname '*secret*' -o -iname '*.pem' \) 2>/dev/null 134 135 # Find files modified in last 7 days 136 find /var/www /tmp -type f -mtime -7 -iname '*config*' 2>/dev/null 137 ``` 138 139 ### Output Interpretation 140 141 1. Full file paths; manually inspect high-value targets (`.conf`, `.cnf`, `.sh`, `.env`, `.bak`) 142 2. **Prioritize:** `/etc`, `/var/www`, `/opt`, `/home`, `/root/.ssh`, `/tmp` 143 144 ### OPSEC and Detection Notes 145 146 1. **LOW NOISE**: locate reads pre-built database (no filesystem traversal; very fast) 147 2. **MODERATE NOISE**: `find /` traverses filesystem; detectable via I/O monitoring 148 3. Target specific directories to minimize footprint: `find /var/www /opt /home` not `find /` 149 150 ### Common Errors 151 152 1. `locate: can not stat` — Database stale; run `updatedb` (requires root) or use find 153 2. `find: permission denied` — Normal for non-root user; redirect stderr with `2>/dev/null` 154 155 ### Version and Platform Notes 156 157 1. locate database location varies: `/var/lib/mlocate/mlocate.db` (Debian/Ubuntu), `/var/db/locate.database` (BSD) 158 2. updatedb runs daily via `/etc/cron.daily/mlocate` on modern Linux 159 160 --- 161 162 ## Phase 2: Targeted File Type Enumeration 163 164 **Purpose:** Enumerate high-value file types (configs, DBs, scripts, backups) before content search 165 166 **Prerequisites:** Standard user access; bash shell 167 168 ### Core Commands 169 170 ```bash 171 # Find all config files 172 find /etc /opt /var/www -type f \( -name '*.conf' -o -name '*.config' -o -name '*.cnf' \) 2>/dev/null 173 174 # Find database files 175 find / -type f \( -name '*.sql' -o -name '*.db' -o -name '*.sqlite*' \) 2>/dev/null 176 177 # Find scripts and environment files 178 find /var/www /opt /home -type f \( -name '*.sh' -o -name '*.env' -o -name '.env' \) 2>/dev/null 179 ``` 180 181 ### Options and Flags 182 183 1. **find -type f** — Regular files only (excludes directories, links) 184 2. **-name 'pattern'** — Case-sensitive name matching 185 3. **-iname 'pattern'** — Case-insensitive name matching 186 4. **-o** — OR operator for multiple name conditions 187 5. **\( \)** — Group multiple conditions 188 189 ### Practical Examples 190 191 ```bash 192 # Configuration file loop (clean output) 193 for ext in conf config cnf; do 194 echo -e "\n=== Files with .$ext extension ==="; 195 find /etc /opt /var/www -name "*.$ext" 2>/dev/null | grep -v 'lib\|fonts\|share\|doc'; 196 done 197 198 # Database file loop with filtering 199 for ext in sql db sqlite sqlite3; do 200 echo -e "\n=== Files with .$ext extension ==="; 201 find / -name "*.$ext" 2>/dev/null | grep -v 'lib\|share\|man\|doc'; 202 done 203 204 # Backup and archive files (high-value targets) 205 find / -type f \( -name '*.bak' -o -name '*.backup' -o -name '*.old' -o -name '*~' \) 2>/dev/null | head -50 206 207 # SSH keys and certificates 208 find / -type f \( -name 'id_rsa' -o -name 'id_dsa' -o -name 'id_ed25519' -o -name '*.pem' -o -name '*.key' \) 2>/dev/null 209 210 # World-readable files (permission misconfiguration) 211 find / -type f -perm -004 -ls 2>/dev/null | grep -v 'proc\|sys\|usr/share' 212 213 # SUID/SGID binaries (potential privilege escalation) 214 find / -type f \( -perm -4000 -o -perm -2000 \) -ls 2>/dev/null 215 ``` 216 217 ### Output Interpretation 218 219 1. Paths to files; next step is content search with grep 220 2. Prioritize small files (`-size -100k`) for faster manual inspection 221 3. Large `.sql` or `.db` files may require [strings](https://man7.org/linux/man-pages/man1/strings.1.html) or specialized tools 222 223 ### OPSEC and Detection Notes 224 225 1. **MODERATE NOISE**: Filesystem traversal generates I/O; EDR may flag rapid enumeration 226 2. Target specific directories first (`/var/www`, `/opt`, `/etc`, `/home`) before whole filesystem 227 3. Exclude noisy system paths with `grep -v` to reduce output volume 228 229 ### Common Errors 230 231 1. `find: missing argument to '-name'` — Quote patterns: `-name '*.conf'` not `-name *.conf` 232 2. Too many results — Add size filters (`-size -10M`), time filters (`-mtime -30`), or path restrictions 233 234 --- 235 236 ## Phase 3: Content Search in Targeted Files 237 238 **Purpose:** Search file contents for credential patterns after identifying target files 239 240 **Prerequisites:** List of target files (from Phase 2); standard user or root access 241 242 ### Core Commands 243 244 ```bash 245 # Pipe find results to grep with xargs (handles spaces) 246 find /etc /opt /var/www -type f -name '*.conf' -print0 | xargs -0 grep -nIi 'password' 2>/dev/null 247 248 # Execute grep on each find result 249 find /var/www -type f \( -name '*.conf' -o -name '*.php' -o -name '*.env' \) -exec grep -HnIi 'password\|api_key' {} \; 2>/dev/null 250 ``` 251 252 ### Options and Flags 253 254 1. **find -print0** — Null-separated output (handles filenames with spaces) 255 2. **xargs -0** — Read null-separated input 256 3. **find -exec grep {} \;** — Execute grep on each file individually 257 4. **grep -H** — Always show filename (critical for multi-file searches) 258 259 ### Practical Examples 260 261 ```bash 262 # Search config files for database credentials 263 find /etc /opt -name '*.conf' -exec grep -HnIi -E 'password|user|host|dbname' {} \; 2>/dev/null 264 265 # Search web app files for API keys 266 find /var/www -type f \( -name '*.php' -o -name '*.py' -o -name '*.js' -o -name '.env' \) -print0 | \ 267 xargs -0 grep -nIi -E 'api[_-]?key|secret|token|auth' 2>/dev/null 268 269 # Search scripts for embedded credentials 270 find /home /opt -name '*.sh' -exec grep -HnIi -E 'export.*PASS|PASSWORD=' {} \; 2>/dev/null 271 272 # Combined file type + content search one-liner 273 find /etc /opt /var/www -type f \( -name '*.conf' -o -name '*.config' -o -name '*.cnf' \) \ 274 -exec grep -Hn 'password\|pass=' {} \; 2>/dev/null | tee config-creds.txt 275 276 # Search only recently modified files (last 30 days) 277 find /var/www -type f -mtime -30 -name '*.conf' -print0 | \ 278 xargs -0 grep -nIi 'password' 2>/dev/null 279 ``` 280 281 ### Output Interpretation 282 283 **Format:** `filename:line_number:matching_line` 284 285 1. Extract values: pipe to `cut`, `awk`, or `sed` for parsing 286 2. Context: use `grep -A 2 -B 2` to see surrounding lines 287 288 ### OPSEC and Detection Notes 289 290 1. **HIGH NOISE**: Reading many files rapidly triggers I/O alerts and auditd logging 291 2. Target smallest file set possible; use Phase 2 filtering aggressively 292 3. Sensitive file access (e.g., `/etc/shadow`, `~/.ssh/id_rsa`) logged by auditd to `/var/log/audit/audit.log` 293 294 ### Common Errors 295 296 1. `xargs: argument line too long` — Large result sets exceed buffer; use `find -exec` instead 297 2. Binary files slow search — Always use `-I` flag with grep to skip binaries 298 3. No output despite known credentials — Check file encoding (`file filename`), SELinux contexts 299 300 --- 301 302 ## Phase 4: History and Environment Inspection 303 304 **Purpose:** Check command history, environment variables, and process memory for credentials 305 306 **Prerequisites:** Standard user or root shell access 307 308 ### Core Commands 309 310 ```bash 311 # Check command history files 312 cat ~/.bash_history ~/.zsh_history 2>/dev/null | grep -i 'pass\|user\|key\|secret' 313 314 # Check current environment variables 315 env | grep -i 'pass\|key\|secret\|token\|api' 316 317 # Check process command lines 318 ps auxww | grep -E 'mysql|psql|ssh|ftp' | grep -v grep 319 ``` 320 321 ### Practical Examples 322 323 ```bash 324 # History files across all users (requires root) 325 find /home /root -type f \( -name '.bash_history' -o -name '.zsh_history' -o -name '.mysql_history' \) \ 326 -exec grep -HnIi -E 'password|pass=|--password' {} \; 2>/dev/null 327 328 # Additional history files 329 cat ~/.lesshst ~/.viminfo ~/.python_history 2>/dev/null | grep -i 'pass' 330 331 # Environment variables from specific process 332 cat /proc/[PID]/environ | tr '\0' '\n' | grep -i 'pass\|key' 333 334 # All process environments (requires root) 335 for pid in $(ls /proc | grep '^[0-9]'); do 336 echo "=== PID $pid ==="; 337 cat /proc/$pid/environ 2>/dev/null | tr '\0' '\n' | grep -iE 'pass|key|secret'; 338 done 339 340 # Database connection strings in process memory (requires root) 341 ps aux | grep -E 'mysql|postgres' | awk '{print $2}' | \ 342 xargs -I {} sh -c 'strings /proc/{}/environ 2>/dev/null | grep -i password' 343 344 # Check systemd service files for credentials 345 grep -rnIi 'Environment=' /etc/systemd/system /usr/lib/systemd/system 2>/dev/null | \ 346 grep -iE 'pass|key|secret' 347 ``` 348 349 ### Output Interpretation 350 351 1. History files may contain credentials passed as CLI arguments 352 2. Environment variables often store DB passwords, API keys, tokens 353 3. Process command lines expose credentials in `--password=value` style arguments 354 4. `/proc/[pid]/environ` contains environment at process launch time 355 356 ### OPSEC and Detection Notes 357 358 1. **LOW NOISE**: Reading history files and env variables minimal impact 359 2. **MODERATE NOISE**: Iterating over all `/proc/[pid]/environ` may trigger EDR alerts 360 3. auditd may log access to specific users' history files if watched 361 362 ### Common Errors 363 364 1. `/proc/[pid]/environ` access denied — Processes owned by other users unreadable without root 365 2. Empty output from `cat /proc/[pid]/environ` — Process exited or no environment variables 366 3. History file not found — User using different shell or history disabled (`HISTFILE=`) 367 368 ### Version and Platform Notes 369 370 1. `/proc` filesystem standard on Linux; not available on BSD/macOS (use `ps e` instead) 371 372 --- 373 374 ## Phase 5: Log File Analysis 375 376 **Purpose:** Search system and application logs for credentials, authentication events, and errors exposing secrets 377 378 **Prerequisites:** Read access to `/var/log` (many logs require root) 379 380 ### Core Commands 381 382 ```bash 383 # Search all log files for password strings 384 grep -rnIi 'password' /var/log 2>/dev/null 385 386 # Search compressed logs with zgrep 387 zgrep -ai 'password\|credential\|secret' /var/log/*.gz 2>/dev/null 388 389 # Loop through logs for authentication events 390 for log in /var/log/*; do 391 grep -iE 'accepted|password|failure' "$log" 2>/dev/null && echo "=== $log ==="; 392 done 393 ``` 394 395 ### Options and Flags 396 397 1. **[zgrep](https://linux.die.net/man/1/zgrep)** — Search compressed files (`.gz`, `.bz2`) 398 2. **zgrep -a** — Treat all files as text (avoids binary detection) 399 3. Standard grep flags apply: `-i`, `-n`, `-E`, `-r` 400 401 ### Practical Examples 402 403 ```bash 404 # SSH authentication logs 405 grep -i 'accepted\|failed' /var/log/auth.log /var/log/secure 2>/dev/null | tail -50 406 407 # Application error logs (may expose DB connection strings) 408 grep -rnIi -E 'error.*password|exception.*credential' /var/log 2>/dev/null 409 410 # Web server logs for API keys in URLs (bad practice but happens) 411 grep -rE 'api_key=|token=' /var/log/apache2 /var/log/nginx 2>/dev/null | head -20 412 413 # Database logs 414 grep -rnIi 'password' /var/log/mysql /var/log/postgresql 2>/dev/null 415 416 # Search compressed logs (older rotated logs) 417 zgrep -aiE 'password=|api_key=|secret=' /var/log/*.gz /var/log/*/*.gz 2>/dev/null | less 418 419 # Conditional log search (only print logs with matches) 420 for logfile in $(ls /var/log/* 2>/dev/null); do 421 RESULT=$(grep -iE 'password|accepted|failure' "$logfile" 2>/dev/null); 422 if $RESULT ; then 423 echo -e "\n=== $logfile ==="; 424 echo "$RESULT" | head -10; 425 fi; 426 done 427 ``` 428 429 ### Output Interpretation 430 431 1. **auth.log/secure:** successful/failed login attempts with usernames 432 2. **Application logs:** stack traces may expose credentials in connection strings 433 3. **Web logs:** API keys or tokens in GET parameters (insecure but common) 434 4. **Look for:** timestamps, usernames, source IPs, credential exposure patterns 435 436 ### OPSEC and Detection Notes 437 438 1. **HIGH ALERT**: Access to `/var/log/auth.log`, `/var/log/secure`, `/var/log/audit/` triggers high-priority alerts 439 2. auditd logs its own file watches to `/var/log/audit/audit.log` — reading this creates recursive log entry 440 3. Legitimate sysadmins read logs frequently; timing and context matter for detection 441 442 ### Common Errors 443 444 1. `grep: /var/log/[file]: Permission denied` — Many logs require root; run as root or use `sudo` 445 2. `zgrep: command not found` — Install gzip utils: `apt install gzip` or `yum install gzip` 446 3. Binary log formats — [systemd journal](https://www.freedesktop.org/software/systemd/man/systemd-journald.service.html) uses binary format; use `journalctl` instead of grep 447 448 ### Version and Platform Notes 449 450 1. Log paths vary: `/var/log/auth.log` (Debian/Ubuntu), `/var/log/secure` (RHEL/CentOS) 451 2. systemd systems: use `journalctl -xe | grep -i password` for systemd journal 452 453 --- 454 455 ## find File Discovery and Filtering 456 457 **Purpose:** Locate files by name, type, size, permissions, modification time before content search 458 459 **Prerequisites:** Standard user access; [GNU findutils](https://www.gnu.org/software/findutils/) 460 461 ### Core Commands 462 463 ```bash 464 # Basic recursive file search 465 find /path -type f -name 'pattern' 2>/dev/null 466 467 # Search with multiple name patterns (OR logic) 468 find / -type f \( -name '*.conf' -o -name '*.config' \) 2>/dev/null 469 470 # Permission-based search 471 find / -type f -perm -004 2>/dev/null 472 ``` 473 474 ### Options and Flags 475 476 1. **-type f** — Regular files only 477 2. **-type d** — Directories only 478 3. **-name 'pattern'** — Case-sensitive name match (shell wildcards: `*`, `?`) 479 4. **-iname 'pattern'** — Case-insensitive name match 480 5. **-perm -mode** — Files with at least these permissions set 481 6. **-perm /mode** — Files with any of these permissions set 482 7. **-user username** — Files owned by user 483 8. **-group groupname** — Files owned by group 484 9. **-size +100M** — Files larger than 100MB (`+` greater, `-` smaller, no prefix exact) 485 10. **-mtime -7** — Modified in last 7 days (`-` within, `+` older than) 486 11. **-atime** — Last access time 487 12. **-ctime** — Last status change time 488 13. **\( \)** — Group multiple expressions 489 14. **-o** — OR operator 490 15. **! or -not** — Negation 491 492 ### Practical Examples 493 494 ```bash 495 # World-writable files (security risk) 496 find / -type f -perm -002 2>/dev/null 497 498 # SUID binaries (privilege escalation vectors) 499 find / -type f -perm -4000 -ls 2>/dev/null 500 501 # Files owned by www-data user 502 find /var/www -user www-data -type f 2>/dev/null 503 504 # Large files (potential DB dumps) 505 find / -type f -size +50M -size -500M 2>/dev/null 506 507 # Recently modified config files (may contain fresh creds) 508 find /etc -type f -name '*.conf' -mtime -7 2>/dev/null 509 510 # SSH keys across all user home directories 511 find /home /root -type f \( -name 'id_rsa' -o -name 'id_dsa' -o -name 'id_ed25519' \) 2>/dev/null 512 513 # Writable directories (potential persistence locations) 514 find / -type d -perm -002 ! -path '/proc/*' ! -path '/sys/*' 2>/dev/null 515 516 # Files with no user ownership (orphaned files) 517 find / -nouser -ls 2>/dev/null 518 ``` 519 520 ### Output Interpretation 521 522 1. Default: full path to matching files 523 2. Use `-ls` for detailed output (permissions, size, owner, timestamp) 524 3. Pipe results to grep, xargs, or `-exec` for further processing 525 526 ### OPSEC and Detection Notes 527 528 1. **MODERATE-HIGH NOISE**: Full filesystem traversal from `/` generates significant I/O 529 2. Target specific directories to reduce footprint 530 3. SUID/permission enumeration is standard attacker behavior; may trigger alerts 531 532 ### Common Errors 533 534 1. `find: missing argument to '-name'` — Quote wildcards: `-name '*.conf'` 535 2. `find: invalid argument '-perm 777'` — Use octal: `-perm 0777` or symbolic: `-perm -u=rwx,g=rwx,o=rwx` 536 3. Parentheses syntax error — Escape with backslash: `\(` `\)` or quote: `'(' ')'` 537 4. Slow search — Exclude large directories: `! -path '/proc/*' ! -path '/sys/*'` 538 539 ### Version and Platform Notes 540 541 1. GNU find (Linux): supports `-printf`, `-regex`, extended options 542 2. BSD find (macOS): limited features; use `-print0` and `xargs -0` for portability 543 544 --- 545 546 ## strings Binary File Extraction 547 548 **Purpose:** Extract printable ASCII strings from binary files (executables, compiled code, memory dumps) 549 550 **Prerequisites:** [GNU binutils](https://www.gnu.org/software/binutils/) installed (standard on Linux) 551 552 ### Core Commands 553 554 ```bash 555 # Extract printable strings from binary 556 strings /path/to/binary 557 558 # Set minimum string length (default 4) 559 strings -n 8 /path/to/binary 560 561 # Search extracted strings for patterns 562 strings /path/to/binary | grep -i 'password\|api\|key' 563 ``` 564 565 ### Options and Flags 566 567 1. **-n [num]** — Minimum string length (default 4; increase to reduce noise) 568 2. **-a** — Scan entire file (default scans only initialized/loaded sections) 569 3. **-t [format]** — Print offset of each string (`o` octal, `x` hex, `d` decimal) 570 4. **-e [encoding]** — Character encoding (`s` 7-bit, `S` 8-bit, `b` 16-bit big-endian, `l` 16-bit little-endian) 571 572 ### Practical Examples 573 574 ```bash 575 # Extract all strings and search for credentials 576 strings /usr/local/bin/app | grep -iE 'password|user|api_key|secret' 577 578 # Extract longer strings to reduce noise 579 strings -n 10 /bin/suspicious | less 580 581 # Extract strings with hex offsets 582 strings -t x /path/to/binary | grep -i 'config' 583 584 # Extract from memory dump or core dump 585 strings /proc/[PID]/mem 2>/dev/null | grep -i 'pass' 586 587 # Extract from all binaries in directory 588 find /usr/local/bin -type f -executable -exec sh -c 'echo "=== {} ==="; strings {} | grep -i password' \; 2>/dev/null 589 590 # Extract from libraries 591 strings /usr/lib/*.so | grep -iE 'password|api_key' | sort -u 592 ``` 593 594 ### Output Interpretation 595 596 1. Raw printable strings; includes code, data, error messages, hardcoded credentials 597 2. High noise-to-signal ratio; use grep filters and increase `-n` value 598 3. **Look for:** connection strings, API endpoints, embedded credentials, license keys 599 600 ### OPSEC and Detection Notes 601 602 1. **LOW NOISE**: strings reads files like cat; minimal detection footprint 603 2. Extracting strings from `/proc/[pid]/mem` requires same user or root; may log access 604 605 ### Common Errors 606 607 1. `strings: [file]: file format not recognized` — File truly not a binary; use `file` to verify 608 2. Excessive output — Increase minimum length: `-n 8` or `-n 12` 609 3. Permission denied on `/proc/[pid]/mem` — Requires root or process owner 610 611 ### Version and Platform Notes 612 613 1. GNU strings (Linux standard): supports all encodings and formats 614 2. BSD strings (macOS): limited encoding support 615 616 --- 617 618 ## Parsing and Filtering Output (awk, sed, cut) 619 620 **Purpose:** Extract and format specific fields from grep/find results 621 622 **Prerequisites:** Standard Linux shell (bash/sh) 623 624 ### Core Commands 625 626 ```bash 627 # awk: split by delimiter and print fields 628 grep 'password=' file.conf | awk -F= '{print $2}' 629 630 # cut: extract column by delimiter 631 grep 'user:' file | cut -d: -f2 632 633 # sed: regex extraction 634 sed -n 's/.*password=\([^&]*\).*/\1/p' file 635 ``` 636 637 ### Options and Flags 638 639 1. **awk -F[char]** — Field separator (default whitespace) 640 2. **awk {print $N}** — Print field N (1-indexed; `$0` entire line) 641 3. **cut -d[char]** — Delimiter character 642 4. **cut -f[N]** — Field number(s) to extract 643 5. **sed -n** — Suppress default output (only print explicit `p` commands) 644 6. **sed s/pattern/replacement/** — Substitute (regex) 645 646 ### Practical Examples 647 648 ```bash 649 # Extract passwords from "password=value" format 650 grep -ri 'password=' /etc | awk -F= '{print $2}' 651 652 # Extract usernames from /etc/passwd (field 1, delimiter :) 653 cut -d: -f1 /etc/passwd 654 655 # Extract usernames and home directories 656 awk -F: '{print $1 " -> " $6}' /etc/passwd 657 658 # Extract database credentials from config 659 grep -E 'user|password|host' db.conf | awk -F= '{print $1 ": " $2}' 660 661 # Extract API keys from grep output (remove filename prefix) 662 grep -rh 'api_key=' /var/www | cut -d= -f2 | sort -u 663 664 # Extract values between quotes 665 sed -n 's/.*password="\([^"]*\)".*/\1/p' config.php 666 667 # Extract IP addresses from logs 668 grep 'Failed password' /var/log/auth.log | awk '{print $11}' | sort | uniq -c | sort -rn 669 670 # Parse JSON-like output (basic) 671 grep -o '"password":"[^"]*"' config.json | cut -d'"' -f4 672 ``` 673 674 ### Output Interpretation 675 676 1. Extracted fields only; ready for further processing or reporting 677 2. Use `sort -u` to deduplicate, `sort | uniq -c` to count occurrences 678 679 ### OPSEC and Detection Notes 680 681 **ZERO IMPACT**: awk/sed/cut operate on stdin/files; no network or unusual syscalls 682 683 ### Common Errors 684 685 1. Wrong field number — Count fields carefully; awk is 1-indexed 686 2. Delimiter not matched — Verify with `head` first; ensure delimiter present 687 3. sed regex not matching — Test pattern with simpler examples; escape special chars 688 689 ### Version and Platform Notes 690 691 1. POSIX-compliant awk/sed/cut work on all Linux/Unix 692 2. [GNU awk (gawk)](https://www.gnu.org/software/gawk/) supports advanced features (multi-char separators, arrays) 693 694 --- 695 696 ## OPSEC and Detection Awareness 697 698 **Purpose:** Understand what defensive tools log when searching for credentials 699 700 **Prerequisites:** Awareness of target environment (auditd, EDR, SIEM presence) 701 702 ### Core Detection Mechanisms 703 704 1. **[auditd](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/chap-system_auditing)** — File access monitoring; logs to `/var/log/audit/audit.log` 705 2. **EDR agents** — Behavioral detection; anomaly scoring for file enumeration patterns 706 3. **syslog** — General system logging; may capture bash history or command execution 707 4. **Process accounting (psacct)** — Logs executed commands 708 709 ### Key Indicators of Compromise (IOCs) Generated 710 711 1. Recursive grep from `/` — High I/O load, CPU spike, massive file read count 712 2. Access to `/etc/shadow`, `/etc/passwd`, `~/.ssh/id_rsa` — High-priority alerts 713 3. Rapid sequential file reads across multiple directories — Anomaly detection trigger 714 4. Large result sets piped to output files — Unusual data exfiltration patterns 715 716 ### Detection Check Commands 717 718 ```bash 719 # Check if auditd is running 720 systemctl status auditd 721 ps aux | grep auditd 722 723 # Check existing audit watches (requires root) 724 auditctl -l 725 726 # Search audit logs for your own activity (requires root) 727 ausearch --file /etc/shadow --interpret 728 ausearch -k password-access -ts recent 729 730 # Check for file watches on sensitive files 731 auditctl -l | grep -E 'shadow|passwd|ssh' 732 733 # Generate audit summary report (requires root) 734 aureport -f | tail -50 735 aureport -u | tail -20 736 737 # Check if EDR/monitoring agent present 738 ps aux | grep -iE 'falcon|crowdstrike|carbon|defender|sentinel|tanium' 739 740 # Check SELinux status (may block file access) 741 sestatus 742 ls -Z /etc/shadow 743 ``` 744 745 ### Output Interpretation 746 747 1. auditd file watches indicate monitored paths 748 2. EDR processes indicate behavioral monitoring active 749 3. SELinux enforcing mode may silently block reads 750 751 ### OPSEC Recommendations 752 753 1. **Target scope aggressively**: Search `/var/www`, `/opt`, specific user homes instead of `/` 754 2. **Exclude system directories**: Use `--exclude-dir={proc,sys,dev,run,usr/share}` with grep 755 3. **Small result sets**: Use `-l` (filenames only) until target narrowed 756 4. **Blend with normal activity**: Sysadmins search logs frequently; timing and context matter 757 5. **Avoid high-value files initially**: Test with lower-risk directories first 758 6. **Throttle I/O**: Add `sleep` between operations or use `nice`/`ionice` to reduce resource impact 759 760 ### Common Detection Artifacts 761 762 1. **`/var/log/audit/audit.log`** — File access records: `type=PATH msg=audit(...): item=0 name="/etc/shadow"` 763 2. **Bash history** — Commands logged to `~/.bash_history` (disable: `unset HISTFILE`) 764 3. **Process command line** — Visible in `ps auxww` output while running 765 4. **Network anomaly** — Large internal file reads may correlate with exfil attempts 766 767 ### Mitigation Against Detection 768 769 1. **Disable history temporarily**: `unset HISTFILE` or `set +o history` 770 2. **Clear history**: `history -c; rm ~/.bash_history` (obvious indicator if monitored) 771 3. **Use absolute paths**: Avoid relative paths that expose working directory context 772 4. **Redirect output carefully**: Large output files in `/tmp` or home directory may trigger alerts 773 774 ### Version and Platform Notes 775 776 1. auditd standard on RHEL/CentOS/Fedora; may not be enabled by default on Debian/Ubuntu 777 2. systemd `journalctl` also logs command execution on systemd-based systems 778 779 --- 780 781 ## References 782 783 1. [GNU grep Manual](https://www.gnu.org/software/grep/manual/grep.html) 784 2. [grep Man Page - Linux.die.net](https://linux.die.net/man/1/grep) 785 3. [locate Man Page](https://man7.org/linux/man-pages/man1/locate.1.html) 786 4. [find Man Page](https://linux.die.net/man/1/find) 787 5. [Linux Privilege Escalation Using Misconfigured File Permissions - Hacking Articles](https://www.hackingarticles.in/linux-privilege-escalation-using-misconfigured-file-permissions/) 788 6. [xargs Man Page](https://man7.org/linux/man-pages/man1/xargs.1.html) 789 7. [Linux find Command - Red Hat Sysadmin](https://www.redhat.com/sysadmin/linux-find-command) 790 8. [Linux /proc Filesystem Documentation](https://www.kernel.org/doc/Documentation/filesystems/proc.txt) 791 9. [ps Man Page](https://linux.die.net/man/1/ps) 792 10. [Linux Log Files Location and Viewing Guide - nixCraft](https://www.cyberciti.biz/faq/linux-log-files-location-and-how-do-i-view-logs-files/) 793 11. [journalctl Man Page](https://man7.org/linux/man-pages/man1/journalctl.1.html) 794 12. [GNU find Manual](https://www.gnu.org/software/findutils/manual/html_mono/find.html) 795 13. [strings Man Page](https://man7.org/linux/man-pages/man1/strings.1.html) 796 14. [awk Man Page](https://man7.org/linux/man-pages/man1/awk.1p.html) 797 15. [GNU sed Manual](https://www.gnu.org/software/sed/manual/sed.html) 798 16. [Understanding Audit Log Files - Red Hat](https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-understanding_audit_log_files) 799 17. [Configuring and Auditing Linux Systems with auditd](https://linux-audit.com/configuring-and-auditing-linux-systems-with-auditd/) 800 801 #Linux #PrivEsc #Enumeration #Credentials #grep #find #OPSEC #Logs #FileEnumeration #PasswordHunting