Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0006 ✕ technique: T1003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Creation of volume shadow copy using vssadmin.exe An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use. Informational Platform Analytics Process execution Credential Access
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
BIOC Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. Informational Platform Analytics Process execution Credential Access
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
Analytics BIOC Suspicious access to shadow file An unpopular process accessed the shadow file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact