Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1003 ✕
Download CSV Show ATT&CK heatmapSuspicious access to shadow file Informational 4 variations
An unpopular process accessed the shadow file.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 7 Days
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: OS Credential Dumping (T1003)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Kubernetes - AGENT, ContainersAttacker's goals: Attackers may attempt to dump the contents of these sensitive files to perform offline password cracking.Investigative actions: Check the process for more suspicious activity. Check whether this was a legitimate action.Variations
Suspicious access to shadow file in a Kubernetes Pod using a known text editor
Medium overridden
An unpopular process accessed the shadow file in a Kubernetes Pod. overridden
Suspicious access to shadow file using a known text editor
Medium overridden
An unpopular process accessed the shadow file. overridden
Suspicious access to shadow file in a Kubernetes Pod
Low overridden
An unpopular process accessed the shadow file. overridden
Suspicious access to shadow file
Low overridden
An unpopular process accessed the shadow file. overridden