Analytics BIOC Informational

Rare process accessed a Keychain file

An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Credentials from Password Stores: Keychain (T1555.001)
Detector tags: Credentials Grabbing Analytics
Attacker's goals:

Obtain access to credentials stored in the Keychain file.

Investigative actions:

Determine whether it is legitimate for the process to access credential data directly. Analyze the process/application that touched the Keychain. Check for any other suspicious actions that were performed by the process. Look for unusual access to resources using credentials stored on said Keychain.

Test period:
N/A (single event)
Deduplication:
1 Day
5 variations:
  • Rare process accessed a Keychain file using the networksetup tool High (parent: Informational) Adds Gather Victim Host Information (T1592)
  • Rare process accessed a Keychain file while installing a new certificate Medium (parent: Informational) Adds Subvert Trust Controls: Install Root Certificate (T1553.004)
  • Rare process accessed a Keychain file initiated by a causality actor with a rare path Low (parent: Informational)
  • Rare process accessed a Keychain file initiated by an unsigned causality actor Low (parent: Informational)
  • Rare unsigned process accessed a Keychain file Low (parent: Informational)