Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕ technique: T1552 ✕
Download CSV Show ATT&CK heatmapSuspicious process accessed certificate files Low
A suspicious process accessed certificate files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Unsecured Credentials (T1552) Steal or Forge Authentication Certificates (T1649)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Attackers may search for local certificate files for authentication, persistence or NTLM extraction.Investigative actions: See whether this was a legitimate action. Follow process/user activities.