Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1555 ✕
Download CSV Show ATT&CK heatmapRare process accessed a Keychain file Informational 5 variations
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores: Keychain (T1555.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Credentials Grabbing AnalyticsAttacker's goals: Obtain access to credentials stored in the Keychain file.Investigative actions: Determine whether it is legitimate for the process to access credential data directly. Analyze the process/application that touched the Keychain. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials stored on said Keychain.Variations
Rare process accessed a Keychain file using the networksetup tool
High overridden
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden
Rare process accessed a Keychain file while installing a new certificate
Medium overridden
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden
Rare process accessed a Keychain file initiated by a causality actor with a rare path
Low overridden
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden
Rare process accessed a Keychain file initiated by an unsigned causality actor
Low overridden
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden
Rare unsigned process accessed a Keychain file
Low overridden
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. overridden