BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
109 BIOCs match the current filters. tactic: TA0005 ✕
Download CSV Show ATT&CK heatmapWindows Firewall disabled via Registry Informational Tampering
An attacker may disable the Windows Firewall via the Registry to bypass network controls.
Indicator:Registry action type = create_registry_key , set_registry_value AND registry value name = donotallowexceptions , enablefirewall AND registry data = 0 AND registry key name = *system\*\services\sharedaccess\parameters\firewallpolicy\* Process initiated by != svchost.exe AND dllhost.exe AND mmc.exe AND sihost.exe AND cgo name != svchost.exe AND dllhost.exe AND mmc.exe AND sihost.exe AND initiator signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash , cgo signature = Signed , Unsigned , N/A , Invalid Signature , Weak Hash AND initiator signer != Symantec Corporation AND CyberArk Software Ltd. AND McAfee, Inc. AND Kaspersky Lab AND Avira Operations GmbH & Co. KG AND F-Secure Corporation AND IBM Corporation AND cgo signer != Symantec Corporation AND CyberArk Software Ltd. AND McAfee, Inc. AND Kaspersky Lab AND Avira Operations GmbH & Co. KG AND F-Secure Corporation AND IBM Corporation Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify System Firewall (T1562.004)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Windows Firewall notifications disabled via Registry Informational Tampering
These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings.
Indicator:Registry registry data = 1 AND registry key name = *system\*\services\sharedaccess\parameters\firewallpolicy\* AND registry value name = disablenotifications AND action type = set_registry_value Process initiator path != *leverit* AND *kaspersky* AND *f-secure* AND cgo path != *leverit* AND *kaspersky* AND *f-secure* AND initiated by != svchost.exe AND dllhost.exe AND cgo name != svchost.exe AND dllhost.exe Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001) Impair Defenses: Disable or Modify System Firewall (T1562.004)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Windows PowerShell Logging being disabled via Registry Informational Evasion
Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell.
Indicator:Registry action type = set_registry_value , delete_registry_value AND registry data = 0 , None AND registry key name = *Policies\Microsoft\Windows\PowerShell\ModuleLogging* AND registry value name = EnableModuleLogging Process initiator cmd != *gpsvc* AND *netsvcs* Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Indicator Blocking (T1562.006)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Windows Registry Editor being disabled via Registry Informational Evasion
Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry.
Indicator:Registry action type = all AND registry data != 0 AND registry key name = *\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System AND registry value name = DisableRegistryTools Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Windows Security audit log was cleared Informational Evasion
Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity.
Indicator:Event Log event log id = 1102 AND event log provider name = Microsoft-Windows-Eventlog Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Indicator Removal (T1070)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Windows Task Manager being disabled via Registry Informational Tampering
Task manager may be disabled to tamper with the user experience and with the response to a malicious incident.
Indicator:Registry action type = all AND registry data = 1 AND registry key name = *\Software\Microsoft\Windows\CurrentVersion\Policies\System AND registry value name = DisableTaskMgr Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Windows event logs cleared using wmic.exe Medium Evasion
Attackers may clear events from Windows event logs to remove traces of their malicious activity.
Indicator:Process action type = execution AND target process cmd = * cleareventlog* AND target process name = wmic.exe
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Indicator Removal (T1070)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Windows process masquerading by an unsigned process Informational Evasion
A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity.
Indicator:Process action type = execution AND target process name = explorer.exe , svchost.exe , winlogon.exe , csrss.exe , lsass.exe , smss.exe , lsm.exe , taskhost.exe , rundll32.exe , dwm.exe , dllhost.exe , services.exe , Taskmgr.exe , wininit.exe AND process execution signer != Microsoft Corporation Host host os = windows
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Masquerading (T1036)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Windows set to permit unsigned drivers (Test Mode) Medium Tampering
This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers.
Indicator:Process action type = execution AND target process cmd = */set*testsigning*on* AND target process name = bcdedit.exe
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses: Disable or Modify Tools (T1562.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11