Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Stored credentials exported using credwiz.exe Low 3 variations

    Attackers may abuse the credwiz tool to export stored accounts.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores (T1555)
    Required data: XDR Agent
    Attacker's goals: An attacker may attempt to gain higher privileges.
    Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.

    Variations

    Stored credentials exported using credwiz.exe using keymgr.dll's KRShowKeyMgr function

    Medium overridden

    Attackers may abuse the credwiz tool to export stored accounts using keymgr.dll's KRShowKeyMgr function. overridden

    Stored credentials exported using credwiz.exe over RDP

    Low overridden

    Attackers may abuse the credwiz tool to export stored accounts over RDP. overridden

    Stored credentials exported using credwiz.exe with a built-in Windows tool

    Low overridden

    Attackers may abuse the credwiz tool to export stored accounts with a built-in Windows tool. overridden