Analytics BIOC
Informational
✕
Suspicious access to shadow file
An unpopular process accessed the shadow file.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: OS Credential Dumping (T1003)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:
Attackers may attempt to dump the contents of these sensitive files to perform offline password cracking.
Investigative actions:
Check the process for more suspicious activity. Check whether this was a legitimate action.
- Test period:
- N/A (single event)
- Deduplication:
- 7 Days
4 variations:
- Suspicious access to shadow file in a Kubernetes Pod using a known text editor Medium (parent: Informational)
- Suspicious access to shadow file using a known text editor Medium (parent: Informational)
- Suspicious access to shadow file in a Kubernetes Pod Low (parent: Informational)
- Suspicious access to shadow file Low (parent: Informational)