Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1555 ✕

Download CSV Show ATT&CK heatmap
  • Unusual access to the AD Sync credential files Informational Cloud 2 variations

    The AD Sync credential files were accessed in an unusual way.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Credentials from Password Stores (T1555)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Attacker's goals: Extracting and decrypting stored Azure AD and Active Directory credentials from Azure AD Connect servers.
    Investigative actions: See whether this was a legitimate action. Follow the causality chain/user/host activities. Follow unusual actions of the AD Sync user. Check for remote SMB connections to the agent. Check for unusual Azure AD authentications. Check if this happened on other endpoints. Check for unusual logins.

    Variations

    Suspicious process access to the AD Sync credential files

    Medium overridden

    The AD Sync credential files were accessed in an unusual way. overridden

    An abnormal process accessed the AD Sync credential files

    Low overridden

    The AD Sync credential files were accessed in an unusual way. overridden