Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
18 detectors match the current filters. technique: T1552 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Cleartext password harvesting using find tools On Windows, the find and findstr tools can be used to find content in files on disk. This rule is looking for cases where the find command is looking for the string 'password', which indicates an attempt to find passwords. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Grepping for passwords Attackers may look for cleartext passwords in files using the grep command. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Key Certificate Search And Exfiltrate Possible attempt to search for key certificates and exfiltrate them. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. | Informational | Platform Analytics | XDR Agent | Credential Access |
| BIOC | LOLBAS reading a Windows credential manager file Encrypted files under the path AppData\Roaming\Microsoft\Credentials are associated with saved passwords in the Windows system. | Informational | Platform Analytics | File | Credential Access |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Reading .ssh files Attackers may gather SSH keys (typically found in the ~/.ssh/ directory) to later use to authenticate with remote SSH servers. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Registry credentials extraction Attackers may extract credentials from the Registry using system commands. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Shell history access Attackers may search historical commands for credentials and information gathering. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | SSH key pair discovery Attackers may look for SSH key pairs using the find command. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Uncommon SQL like command line Uncommon SQL query in command line of an executed process. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unusual ADConnect database file access An unusual process accessed the ADConnect database files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |