Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Rare process accessed a Keychain file Informational 5 variations

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores: Keychain (T1555.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Credentials Grabbing Analytics
    Attacker's goals: Obtain access to credentials stored in the Keychain file.
    Investigative actions: Determine whether it is legitimate for the process to access credential data directly. Analyze the process/application that touched the Keychain. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials stored on said Keychain.

    Variations

    Rare process accessed a Keychain file using the networksetup tool

    High overridden

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden

    Rare process accessed a Keychain file while installing a new certificate

    Medium overridden

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden

    Rare process accessed a Keychain file initiated by a causality actor with a rare path

    Low overridden

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden

    Rare process accessed a Keychain file initiated by an unsigned causality actor

    Low overridden

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden

    Rare unsigned process accessed a Keychain file

    Low overridden

    An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden