Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1552 ✕
Download CSV Show ATT&CK heatmapSuspicious access to cloud credential files Informational Cloud 6 variations
A process accessed multiple cloud credential files, which may indicate a credential theft activity.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Cloud Lateral Movement AnalyticsAttacker's goals: Gain initial access to the cloud environment.Investigative actions: Verify if the executing process is doing more suspicious activities. Verify if the exposed credential files were used to access to the cloud environment. Verify which operations were used against the cloud environment with the exposed credentials.Variations
Suspicious access to cloud credential files of various cloud providers within a cloud instance
Low overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden
Suspicious access to cloud credential files within a cloud instance
Informational overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden
Suspicious access to Windows cloud credential files of various cloud providers
Medium overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden
Suspicious access to Windows cloud credential files by an unusual process
Low overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden
Suspicious access to cloud credential files of various cloud providers
Medium overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden
Suspicious access to cloud credential files by an unusual process
Low overridden
A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden