Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

16 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Access to kubelet credentials file A process accessed a kubelet credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. High Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Credential Access
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Keylogging using system commands Usage of a Linux system utility to capture input. Low Platform Analytics XDR Agent Credential Access, Collection
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
Analytics Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Suspicious access to shadow file An unpopular process accessed the shadow file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. Informational Cortex Cloud XDR Agent Credential Access
Analytics BIOC Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access