Analytics BIOC Informational

Suspicious access to shadow file

An unpopular process accessed the shadow file.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Attackers may attempt to dump the contents of these sensitive files to perform offline password cracking.

Investigative actions:

Check the process for more suspicious activity. Check whether this was a legitimate action.

Test period:
N/A (single event)
Deduplication:
7 Days
4 variations:
  • Suspicious access to shadow file in a Kubernetes Pod using a known text editor Medium (parent: Informational)
  • Suspicious access to shadow file using a known text editor Medium (parent: Informational)
  • Suspicious access to shadow file in a Kubernetes Pod Low (parent: Informational)
  • Suspicious access to shadow file Low (parent: Informational)