Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

21 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
BIOC Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. Medium Platform Analytics Process execution Credential Access
BIOC Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. Medium Platform Analytics Process execution Credential Access
BIOC Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. Medium Platform Analytics Process execution Credential Access
BIOC Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. Medium Platform Analytics Process execution Discovery, Credential Access
BIOC Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. Medium Platform Analytics Process execution Credential Access
Analytics BIOC LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. Medium Platform Analytics Process execution Credential Access
Analytics NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
BIOC PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. Medium Platform Analytics Process execution Credential Access
Analytics BIOC Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. Medium Platform Analytics XDR Agent Defense Evasion, Credential Access
Analytics BIOC Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Collection