Analytics Informational

Suspicious access to cloud credential files

A process accessed multiple cloud credential files, which may indicate a credential theft activity.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Unsecured Credentials: Credentials In Files (T1552.001)
Detector tags: Cloud Lateral Movement Analytics
Attacker's goals:

Gain initial access to the cloud environment.

Investigative actions:

Verify if the executing process is doing more suspicious activities. Verify if the exposed credential files were used to access to the cloud environment. Verify which operations were used against the cloud environment with the exposed credentials.

Test period:
10 Minutes
Deduplication:
1 Day
6 variations:
  • Suspicious access to cloud credential files of various cloud providers within a cloud instance Low (parent: Informational)
  • Suspicious access to cloud credential files within a cloud instance Informational
  • Suspicious access to Windows cloud credential files of various cloud providers Medium (parent: Informational)
  • Suspicious access to Windows cloud credential files by an unusual process Low (parent: Informational)
  • Suspicious access to cloud credential files of various cloud providers Medium (parent: Informational)
  • Suspicious access to cloud credential files by an unusual process Low (parent: Informational)