Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

9 detectors match the current filters. technique: T1552 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Uncommon SQL like command line Uncommon SQL query in command line of an executed process. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. Low Platform Analytics XDR Agent Credential Access