Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0006 ✕
Download CSV Show ATT&CK heatmapUncommon access to cloud platforms' sensitive files by a scripting engine Informational 1 variation
A scripting engine has accessed sensitive cloud platforms' files.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Credentials from Password Stores (T1555)Required data: XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Gain access/control over internal cloud platforms or repositories.Investigative actions: Investigate if the behavior is known to the user or part of known product's procedure. Investigate if the actor processes command line contains malicious indicators or a script file.Variations
Uncommon access to cloud platforms' sensitive files by an uncommon script or utility
Low overridden
A scripting engine has accessed sensitive cloud platforms' files. overridden