Search and filter across all detection sources
2,512 rules
[WINDOWS-SECURITY] Credential Manager credentials were backed up
[WINDOWS-SECURITY] Credential Manager credentials were restored from a backup
PowerShell Credential Prompt
Detects PowerShell calling a credential prompt
SSH Credentials Changed
Detects when SSH credentials are updated.
[MICROSOFT-ATP] CredentialAccess alert
[NETSKOPE] Compromised Credential alert
[ONELOGIN] API_CREDENTIAL_CREATED
[ONELOGIN] API_CREDENTIAL_DELETED
[ONELOGIN] API_CREDENTIAL_DISABLED
[ONELOGIN] API_CREDENTIAL_ENABLED
[SALESFORCE] CredentialStuffingEvent event detected
[SOPHOS] Invalid AWS credentials
[SOPHOS] Invalid Azure credentials
[VEEAM] Credential Record Deleted
[VEEAM] Credential Record Updated
[VEEAM] SSH Credentials Changed
Windows Credential Manager Access via VaultCmd
List credentials currently stored in Windows Credential Manager via the native Windows utility vaultcmd.exe
Flare leaked credentials results
'This query searches for leaked credential events.'
Added Credentials to Existing Application
Detects when a new credential is added to an existing application. Any additional credentials added outside of expected processes could be a malicious actor using those credentials.
Outgoing Logon with New Credentials
Detects logon events that specify new credentials