Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
23 detectors match the current filters. technique: T1555 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An Azure Key Vault key was modified An Azure Key Vault key was modified. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| BIOC | Credentials from Web Browsers Detects attempt to copy browser files to acquire credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Certificate Access Detected access to Keychain certificates. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Import Item An item was imported from the Keychain. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Unlock Detected Keychain unlocking. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Password-related Mozilla files were read by a non-Mozilla process Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| Analytics BIOC | Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| BIOC | Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| Analytics BIOC | Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| BIOC | Web browser cookie and credential access Detect attempt to acquire cookies or credentials from a Safari browser. | Informational | Platform Analytics | Process execution | Credential Access |