BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

109 BIOCs match the current filters. tactic: TA0005 ✕

Download CSV Show ATT&CK heatmap
  • Windows Firewall disabled via Registry Informational Tampering

    An attacker may disable the Windows Firewall via the Registry to bypass network controls.

    Indicator:

    Registry action type = create_registry_key , set_registry_value AND registry value name = donotallowexceptions , enablefirewall AND registry data = 0 AND registry key name = *system\*\services\sharedaccess\parameters\firewallpolicy\* Process initiated by != svchost.exe AND dllhost.exe AND mmc.exe AND sihost.exe AND cgo name != svchost.exe AND dllhost.exe AND mmc.exe AND sihost.exe AND initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Symantec Corporation AND CyberArk Software Ltd. AND McAfee, Inc. AND Kaspersky Lab AND Avira Operations GmbH & Co. KG AND F-Secure Corporation AND IBM Corporation AND cgo signer != Symantec Corporation AND CyberArk Software Ltd. AND McAfee, Inc. AND Kaspersky Lab AND Avira Operations GmbH & Co. KG AND F-Secure Corporation AND IBM Corporation Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Windows Firewall notifications disabled via Registry Informational Tampering

    These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings.

    Indicator:

    Registry registry data = 1 AND registry key name = *system\*\services\sharedaccess\parameters\firewallpolicy\* AND registry value name = disablenotifications AND action type = set_registry_value Process initiator path != *leverit* AND *kaspersky* AND *f-secure* AND cgo path != *leverit* AND *kaspersky* AND *f-secure* AND initiated by != svchost.exe AND dllhost.exe AND cgo name != svchost.exe AND dllhost.exe Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001) Impair Defenses: Disable or Modify System Firewall (T1562.004)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Windows PowerShell Logging being disabled via Registry Informational Evasion

    Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell.

    Indicator:

    Registry action type = set_registry_value , delete_registry_value AND registry data = 0 , None AND registry key name = *Policies\Microsoft\Windows\PowerShell\ModuleLogging* AND registry value name = EnableModuleLogging Process initiator cmd != *gpsvc* AND *netsvcs* Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Indicator Blocking (T1562.006)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Windows Registry Editor being disabled via Registry Informational Evasion

    Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry.

    Indicator:

    Registry action type = all AND registry data != 0 AND registry key name = *\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System AND registry value name = DisableRegistryTools Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Windows Security audit log was cleared Informational Evasion

    Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity.

    Indicator:

    Event Log event log id = 1102 AND event log provider name = Microsoft-Windows-Eventlog Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Indicator Removal (T1070)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Windows Task Manager being disabled via Registry Informational Tampering

    Task manager may be disabled to tamper with the user experience and with the response to a malicious incident.

    Indicator:

    Registry action type = all AND registry data = 1 AND registry key name = *\Software\Microsoft\Windows\CurrentVersion\Policies\System AND registry value name = DisableTaskMgr Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Windows event logs cleared using wmic.exe Medium Evasion

    Attackers may clear events from Windows event logs to remove traces of their malicious activity.

    Indicator:

    Process action type = execution AND target process cmd = * cleareventlog* AND target process name = wmic.exe

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Indicator Removal (T1070)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Windows process masquerading by an unsigned process Informational Evasion

    A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity.

    Indicator:

    Process action type = execution AND target process name = explorer.exe , svchost.exe , winlogon.exe , csrss.exe , lsass.exe , smss.exe , lsm.exe , taskhost.exe , rundll32.exe , dwm.exe , dllhost.exe , services.exe , Taskmgr.exe , wininit.exe AND process execution signer != Microsoft Corporation Host host os = windows

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Masquerading (T1036)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Windows set to permit unsigned drivers (Test Mode) Medium Tampering

    This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers.

    Indicator:

    Process action type = execution AND target process cmd = */set*testsigning*on* AND target process name = bcdedit.exe

    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11