Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

13 detectors match the current filters. technique: T1552 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics BIOC Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Uncommon SQL like command line Uncommon SQL query in command line of an executed process. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. Informational Cortex Cloud XDR Agent Credential Access