Analytics BIOC
Informational
✕
Rare process accessed a Keychain file
An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Keychain (T1555.001)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:
Obtain access to credentials stored in the Keychain file.
Investigative actions:
Determine whether it is legitimate for the process to access credential data directly. Analyze the process/application that touched the Keychain. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials stored on said Keychain.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
5 variations:
- Rare process accessed a Keychain file using the networksetup tool High (parent: Informational) Adds Gather Victim Host Information (T1592)
- Rare process accessed a Keychain file while installing a new certificate Medium (parent: Informational) Adds Subvert Trust Controls: Install Root Certificate (T1553.004)
- Rare process accessed a Keychain file initiated by a causality actor with a rare path Low (parent: Informational)
- Rare process accessed a Keychain file initiated by an unsigned causality actor Low (parent: Informational)
- Rare unsigned process accessed a Keychain file Low (parent: Informational)