Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
18 detectors match the current filters. technique: T1552 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. | Low | Cortex Cloud | Gcp Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. | Low | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access, Execution |
| Analytics BIOC | A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| Analytics BIOC | Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. | Low | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Suspicious process accessed certificate files A suspicious process accessed certificate files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon Azure Cosmos DB master key read by identity A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity. | Low | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |