Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking.

Tactics
TA0006

Sub-technique of
T1003


See: MITRE ATT&CK