Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1552 ✕

Download CSV Show ATT&CK heatmap
  • Suspicious access to cloud credential files Informational Cloud 6 variations

    A process accessed multiple cloud credential files, which may indicate a credential theft activity.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Cloud Lateral Movement Analytics
    Attacker's goals: Gain initial access to the cloud environment.
    Investigative actions: Verify if the executing process is doing more suspicious activities. Verify if the exposed credential files were used to access to the cloud environment. Verify which operations were used against the cloud environment with the exposed credentials.

    Variations

    Suspicious access to cloud credential files of various cloud providers within a cloud instance

    Low overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden

    Suspicious access to cloud credential files within a cloud instance

    Informational overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden

    Suspicious access to Windows cloud credential files of various cloud providers

    Medium overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden

    Suspicious access to Windows cloud credential files by an unusual process

    Low overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden

    Suspicious access to cloud credential files of various cloud providers

    Medium overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden

    Suspicious access to cloud credential files by an unusual process

    Low overridden

    A process accessed multiple cloud credential files, which may indicate a credential theft activity. overridden