Uncommon attempt at grabbing credentials from a sensitive file
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Credentials Grabbing Analytics
ATT&CK Tactic
Credential Access (TA0006), Discovery (TA0007)
ATT&CK Technique
OS Credential Dumping (T1003), Unsecured Credentials: Credentials In Files (T1552.001), Unsecured Credentials (T1552), Credentials from Password Stores (T1555), Account Discovery (T1087)
Severity
Informational
Description
A process made an uncommon attempt to access a file that may contain sensitive information.
Attacker's Goals
Attackers may attempt to access sensitive files to steal credentials, perform reconnaissance on system configurations and users, and find pathways for lateral movement.
Investigative actions
Review the event's context - examine the process, its command line, and its origin to gain a comprehensive understanding of the anomalous access.* Assess the behavior's legitimacy: Given that this is an uncommon event, determine if this file access is an expected and authorized behavior for the actor process.
Variations
Was this helpful?
