Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
123 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| BIOC | Cleartext password harvesting using find tools On Windows, the find and findstr tools can be used to find content in files on disk. This rule is looking for cases where the find command is looking for the string 'password', which indicates an attempt to find passwords. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. | High | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. | Low | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Creation of volume shadow copy using vssadmin.exe An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credentials from Web Browsers Detects attempt to copy browser files to acquire credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping Registry hives with passwords Dumping registry hives can be used to obtain stored credentials/hashes. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| Analytics BIOC | Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. | Low | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| Analytics BIOC | FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| BIOC | Grepping for passwords Attackers may look for cleartext passwords in files using the grep command. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | GUI Input Capture Prompt user to supply a password in response to a System Preference dialog pop up message. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Installation of Cain & Abel password recovery tool A process created a Registry key associated with the common password cracking tool Cain & Abel. | Low | Platform Analytics | Registry | Credential Access |
| BIOC | Internet Explorer home page modification The Internet Explorer home page could be changed to a malicious page. | Low | Platform Analytics | Registry | Impact, Credential Access |
| BIOC | Kerberos brute-force attack using Kerbrute This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| BIOC | Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. | High | Platform Analytics | Process execution | Credential Access, Lateral Movement |
| BIOC | Key Certificate Search And Exfiltrate Possible attempt to search for key certificates and exfiltrate them. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Certificate Access Detected access to Keychain certificates. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Import Item An item was imported from the Keychain. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Unlock Detected Keychain unlocking. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Keylogging using system commands Usage of a Linux system utility to capture input. | Low | Platform Analytics | XDR Agent | Credential Access, Collection |
| Analytics BIOC | Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. | Informational | Platform Analytics | XDR Agent | Credential Access |
| BIOC | LOLBAS reading a Windows credential manager file Encrypted files under the path AppData\Roaming\Microsoft\Credentials are associated with saved passwords in the Windows system. | Informational | Platform Analytics | File | Credential Access |
| Analytics BIOC | LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access, Lateral Movement |
| Analytics BIOC | Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Modification of NTLM restrictions in the Registry Allowing the transmission of NTLM could be part of an NTLM downgrade or an Internal Monologue attack. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics | Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | Multiple uncommon SSH Servers with the same Server host key Multiple uncommon SSH servers were observed using the same host key. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics | Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| BIOC | Nagios enumeration A Nagios XI database may be enumerated for the credentials of the hosts monitored. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | NTDS.dit file written by an uncommon executable The Active Directory database file was written by an uncommon process to a non-default location. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | File | Credential Access |
| BIOC | NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics | NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access, Lateral Movement |
| BIOC | Password-related Mozilla files were read by a non-Mozilla process Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Pluggable Authentication Modules Access Access to Pluggable Authentication Modules. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Pluggable Authentication Modules Modification Modification of Pluggable Authentication Modules. | Informational | Platform Analytics | File | Credential Access |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible Kerberoasting without SPNs A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| BIOC | Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | High | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible Search For Password Files Attackers often search for files that have passwords in them. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics | Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Credential Access |
| Analytics BIOC | Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Reading .ssh files Attackers may gather SSH keys (typically found in the ~/.ssh/ directory) to later use to authenticate with remote SSH servers. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. | Low | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Registry credentials extraction Attackers may extract credentials from the Registry using system commands. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | File | Credential Access, Collection |
| BIOC | Shell history access Attackers may search historical commands for credentials and information gathering. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | Process execution | Credential Access, Collection |
| BIOC | SSH key pair discovery Attackers may look for SSH key pairs using the find command. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Certutil AD CS contact A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface. | Low | Platform Analytics | XDR Agent | Discovery, Credential Access |
| BIOC | Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. | High | Platform Analytics | File | Credential Access |
| Analytics BIOC | Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious LDAP queries followed by shared folder access The user executed suspicious LDAP queries shortly before accessing a shared folder. This behavior may be indicative of Rubeus activity involving Kerberos ticket forgery, such as Golden Ticket or Silver Ticket attacks. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious process accessed certificate files A suspicious process accessed certificate files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious setspn.exe execution A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast". | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. | Medium | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. | Low | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |