Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
64 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A process queried the ADFS database decryption key via LDAP A process queried the ADFS database decryption key (DKM key) via LDAP. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user created a pfx file for the first time A user created a pfx file for the first time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | A user sent multiple TGT requests to irregular service A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Privilege Escalation |
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. | Low | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. | High | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Credential Access |
| Analytics BIOC | Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Modification of NTLM restrictions in the Registry Allowing the transmission of NTLM could be part of an NTLM downgrade or an Internal Monologue attack. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | NTDS.dit file written by an uncommon executable The Active Directory database file was written by an uncommon process to a non-default location. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious access to cloud credential files A process accessed multiple cloud credential files, which may indicate a credential theft activity. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious Kerberos Pre-Auth Failures by Host An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious LDAP queries followed by shared folder access The user executed suspicious LDAP queries shortly before accessing a shared folder. This behavior may be indicative of Rubeus activity involving Kerberos ticket forgery, such as Golden Ticket or Silver Ticket attacks. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Print System Remote Protocol usage by a process A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious process accessed certificate files A suspicious process accessed certificate files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Uncommon creation or access operation of sensitive shadow copy An uncommon creation or access of a sensitive Shadow Copy volume path. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon sensitive registry hive dump A sensitive registry hive was extracted, which is used for accessing credentials. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Collection |
| Analytics BIOC | Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual ADConnect database file access An unusual process accessed the ADConnect database files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual CertLog Remote File Write A remote host wrote to a certificate log file via RPC over SMB, which may indicate the use of an AD CS attack tool like Certipy. This behavior is commonly associated with certificate-based authentication attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Encrypting File System Remote call (EFSRPC) to domain controller An unusual Encrypting File System Remote call (EFSRPC) was made to a domain controller. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |