T1003.007
OS Credential Dumping: Proc Filesystem
discovered 2026-08-04CI runner process memory scraping via sudo python3 reading /proc/{pid}/mem to extract GitHub Actions masked secrets. Targets the Runner.Worker internal JSON structure where secret values are stored in plaintext.
View on MITRE ATT&CK