Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

34 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user created a pfx file for the first time A user created a pfx file for the first time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Privilege Escalation
Analytics BIOC Access to kubelet credentials file A process accessed a kubelet credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
Analytics BIOC PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Suspicious access to cloud credential files A process accessed multiple cloud credential files, which may indicate a credential theft activity. Informational Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious access to shadow file An unpopular process accessed the shadow file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. Informational Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual ADConnect database file access An unusual process accessed the ADConnect database files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access