Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
49 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Cleartext password harvesting using find tools On Windows, the find and findstr tools can be used to find content in files on disk. This rule is looking for cases where the find command is looking for the string 'password', which indicates an attempt to find passwords. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Creation of volume shadow copy using vssadmin.exe An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credentials from Web Browsers Detects attempt to copy browser files to acquire credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping Registry hives with passwords Dumping registry hives can be used to obtain stored credentials/hashes. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| BIOC | Grepping for passwords Attackers may look for cleartext passwords in files using the grep command. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | GUI Input Capture Prompt user to supply a password in response to a System Preference dialog pop up message. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Installation of Cain & Abel password recovery tool A process created a Registry key associated with the common password cracking tool Cain & Abel. | Low | Platform Analytics | Registry | Credential Access |
| BIOC | Internet Explorer home page modification The Internet Explorer home page could be changed to a malicious page. | Low | Platform Analytics | Registry | Impact, Credential Access |
| BIOC | Kerberos brute-force attack using Kerbrute This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. | High | Platform Analytics | Process execution | Credential Access, Lateral Movement |
| BIOC | Key Certificate Search And Exfiltrate Possible attempt to search for key certificates and exfiltrate them. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Certificate Access Detected access to Keychain certificates. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Import Item An item was imported from the Keychain. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Keychain Unlock Detected Keychain unlocking. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | LOLBAS reading a Windows credential manager file Encrypted files under the path AppData\Roaming\Microsoft\Credentials are associated with saved passwords in the Windows system. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Nagios enumeration A Nagios XI database may be enumerated for the credentials of the hosts monitored. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | File | Credential Access |
| BIOC | NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Password-related Mozilla files were read by a non-Mozilla process Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Pluggable Authentication Modules Access Access to Pluggable Authentication Modules. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Pluggable Authentication Modules Modification Modification of Pluggable Authentication Modules. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |
| BIOC | PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Reading .ssh files Attackers may gather SSH keys (typically found in the ~/.ssh/ directory) to later use to authenticate with remote SSH servers. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Registry credentials extraction Attackers may extract credentials from the Registry using system commands. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | File | Credential Access, Collection |
| BIOC | Shell history access Attackers may search historical commands for credentials and information gathering. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | Process execution | Credential Access, Collection |
| BIOC | SSH key pair discovery Attackers may look for SSH key pairs using the find command. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. | High | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Web browser cookie and credential access Detect attempt to acquire cookies or credentials from a Safari browser. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |
| BIOC | WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. | Informational | Platform Analytics | Process execution | Credential Access, Impact |