Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user sent multiple TGT requests to irregular service A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. Low Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
Analytics Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access