Detection rules
native correlation · credential access

Obfuscated credential harvesting and exfiltration

obfuscated-credential-harvesting-exfiltration

A structurally obfuscated executable bundle combines multi-family credential targeting, local collection, and outbound payload transfer.

Default severityHIGHEvidence classcorrelated
What it means

Read the evidence before the label.

This alert records correlated evidence produced by the native correlation analyzer. Its default severity describes potential impact, not certainty that an extension is malicious.

A final decision also considers evidence correlation, artifact identity, analysis coverage, and the active policy.

Expected evidence

Exact extension version, artifact hash, affected file or dependency, normalized rule identifier, confidence, and scanner ruleset.

Reviewer action

Confirm whether the behavior matches the extension’s declared purpose and whether execution requires explicit user intent.

Find extensions in the catalog