Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

39 detectors match the current filters. tactic: TA0006 ✕ technique: T1003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. Low Platform Analytics XDR Agent Credential Access, Discovery
BIOC Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. High Platform Analytics Process execution Credential Access
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
BIOC Creation of volume shadow copy using vssadmin.exe An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use. Informational Platform Analytics Process execution Credential Access
BIOC Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. High Platform Analytics Process execution Credential Access
BIOC Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. Medium Platform Analytics Process execution Credential Access
BIOC Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. Medium Platform Analytics Process execution Credential Access
BIOC Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. Medium Platform Analytics Process execution Credential Access
BIOC Dumping Registry hives with passwords Dumping registry hives can be used to obtain stored credentials/hashes. Low Platform Analytics Process execution Credential Access
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
BIOC Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. Medium Platform Analytics Process execution Credential Access
BIOC Installation of Cain & Abel password recovery tool A process created a Registry key associated with the common password cracking tool Cain & Abel. Low Platform Analytics Registry Credential Access
Analytics BIOC LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Modification of NTLM restrictions in the Registry Allowing the transmission of NTLM could be part of an NTLM downgrade or an Internal Monologue attack. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Nagios enumeration A Nagios XI database may be enumerated for the credentials of the hosts monitored. Low Platform Analytics Process execution Credential Access
BIOC Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. Informational Platform Analytics Process execution Credential Access
Analytics BIOC NTDS.dit file written by an uncommon executable The Active Directory database file was written by an uncommon process to a non-default location. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics File Credential Access
BIOC NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. Medium Platform Analytics Process execution Credential Access
Analytics BIOC Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
BIOC Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. High Platform Analytics Process execution Credential Access
BIOC PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. Medium Platform Analytics Process execution Credential Access
Analytics BIOC Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. Medium Platform Analytics XDR Agent Defense Evasion, Credential Access
Analytics BIOC Suspicious access to shadow file An unpopular process accessed the shadow file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. High Platform Analytics File Credential Access
Analytics BIOC Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon creation or access operation of sensitive shadow copy An uncommon creation or access of a sensitive Shadow Copy volume path. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon sensitive registry hive dump A sensitive registry hive was extracted, which is used for accessing credentials. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact