Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
27 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A process queried the ADFS database decryption key via LDAP A process queried the ADFS database decryption key (DKM key) via LDAP. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user created a pfx file for the first time A user created a pfx file for the first time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | A user sent multiple TGT requests to irregular service A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Privilege Escalation |
| Analytics BIOC | Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious Kerberos Pre-Auth Failures by Host An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Print System Remote Protocol usage by a process A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual CertLog Remote File Write A remote host wrote to a certificate log file via RPC over SMB, which may indicate the use of an AD CS attack tool like Certipy. This behavior is commonly associated with certificate-based authentication attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Encrypting File System Remote call (EFSRPC) to domain controller An unusual Encrypting File System Remote call (EFSRPC) was made to a domain controller. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |