Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

15 detectors match the current filters. technique: T1555 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An Azure Key Vault key was modified An Azure Key Vault key was modified. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. Informational Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual secret management activity A cloud Identity performed a secret management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access