Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

14 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. High Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Credential Access
BIOC Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. High Platform Analytics Process execution Credential Access
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
BIOC Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. High Platform Analytics Process execution Credential Access
Analytics BIOC Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. High Platform Analytics XDR Agent Credential Access
BIOC Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. High Platform Analytics Process execution Credential Access, Lateral Movement
Analytics BIOC Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. High Platform Analytics XDR Agent Credential Access
BIOC Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics File Credential Access
Analytics Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). High Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. High Platform Analytics Process execution Credential Access
BIOC Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. High Platform Analytics File Credential Access
Analytics BIOC Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics XDR Agent Credential Access