Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
13 detectors match the current filters. tactic: TA0006 ✕ technique: T1552 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. | Informational | Identity Analytics | XDR Agent | Credential Access, Privilege Escalation |
| Analytics BIOC | Possible Search For Password Files Attackers often search for files that have passwords in them. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Uncommon SQL like command line Uncommon SQL query in command line of an executed process. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |