• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Post-exploitation grep sweep for API keys and credential files

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 24 days ago•0•0•1

    Detects automated searching (via grep, findstr, or select-string) for sensitive strings (e.g., API keys, private keys, wallet data) across multiple occurrences on a single host, or the creation of suspicious sensitive files (e.g., .env, credentials, wallet.dat) on devices where such automated sweeping activity has been observed. This pattern indicates an adversary staging data for exfiltration.

    Microsoft Sentinel (KQL)

    Tags

    T1552.001 - Credentials In FilesT1005 - Data from Local SystemTA0009 - CollectionProcess CreationFile CreationCredential AccessData StagingWindowsLinuxWindows SysmonWindows Defender Atpkql

    Found in

    • Rise of Agentic Ransomware: JADEPUFFER and FortiBleedLast updated 24 days ago
    • Rise of Agentic Ransomware: JADEPUFFER and FortiBleedLast updated 24 days ago
    • Rise of Agentic Ransomware: JADEPUFFER and FortiBleedLast updated 24 days ago
    • Rise of Agentic Ransomware: JADEPUFFER and FortiBleedLast updated 24 days ago
    • Rise of Agentic Ransomware: JADEPUFFER and FortiBleedLast updated 24 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?