Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. | High | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Credential Access |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Keylogging using system commands Usage of a Linux system utility to capture input. | Low | Platform Analytics | XDR Agent | Credential Access, Collection |
| Analytics BIOC | Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics | Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |
| Analytics BIOC | Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |