Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
22 detectors match the current filters. technique: T1003 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Creation of volume shadow copy using vssadmin.exe An attacker may create volume shadow copies to gain access to protected or locked files, whereas backup is the common legitimate use. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Dumping Registry hives with passwords Dumping registry hives can be used to obtain stored credentials/hashes. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| BIOC | Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Installation of Cain & Abel password recovery tool A process created a Registry key associated with the common password cracking tool Cain & Abel. | Low | Platform Analytics | Registry | Credential Access |
| BIOC | Nagios enumeration A Nagios XI database may be enumerated for the credentials of the hosts monitored. | Low | Platform Analytics | Process execution | Credential Access |
| BIOC | Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | File | Credential Access |
| BIOC | NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | High | Platform Analytics | Process execution | Credential Access |
| BIOC | PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. | High | Platform Analytics | File | Credential Access |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |
| BIOC | WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. | Informational | Platform Analytics | Process execution | Credential Access, Impact |