Suspicious access to cloud credential files
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
10 Minutes
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Cloud
Detector Tags
Cloud Lateral Movement Analytics
ATT&CK Tactic
Credential Access (TA0006)
ATT&CK Technique
Unsecured Credentials: Credentials In Files (T1552.001)
Severity
Informational
Description
A process accessed multiple cloud credential files, which may indicate a credential theft activity.
Attacker's Goals
Gain initial access to the cloud environment.
Investigative actions
Verify if the executing process is doing more suspicious activities.
Verify if the exposed credential files were used to access to the cloud environment.
Verify which operations were used against the cloud environment with the exposed credentials.
Variations
Was this helpful?
