BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
11 BIOCs match the current filters. tactic: TA0001 ✕
Download CSV Show ATT&CK heatmapAdobe Acrobat Reader drops an executable file to disk Informational Dropper
The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.
Indicator:File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Adobe reader spawns a browser Informational Dropper
If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts.
Indicator:Process action type = execution AND target process name = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe Process initiated by = acrord32.exe , cgo name = acrord32.exe AND initiator signer = *adobe systems* , cgo signer = *adobe systems* AND initiator signature = Signed , cgo signature = Signed Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Excel Web Query file created on disk Informational Infiltration
Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads.
Indicator:File file name = *.iqy AND action type = create
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Exchange process writing aspx files High Infiltration
An exchange process is writing to .aspx files. This may be an actor dropping web shells.
Indicator:File action type = create , write AND file path =~ (\\inetpub\\wwwroot\\aspnet_client\\|\\frontend\\httpproxy\\owa\\auth\\|\\frontend\\httpproxy\\ecp\\auth\\).*\.aspx Process initiated by = UMWorkerProcess.exe , w3wp.exe
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Exploit Public-Facing Application (T1190) Application Layer Protocol: Web Protocols (T1071.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Office document embeds a .LNK file Informational Execution
An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file.
Indicator:Process action type = execution AND target process cmd = *{00021401-0000-0000-C000-000000000046}* Process initiated by = winword.exe , excel.exe , powerpnt.exe Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Office process spawns verclsid.exe Informational Execution
A Microsoft Office process launching verclsid.exe may be a sign of phishing.
Indicator:Process action type = execution AND target process name = verclsid.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Out of band testing domain connection Low Infiltration
Connection from web service process to out-of-band-testing domain.
Indicator:Network action type = outgoing , failed , raw_packet AND remote host =~ burpcollabat\.net|canarytokens\.com|dnslog\.cn|interact\.sh|interactsh\.com|oast\.fun|oast\.live|oast\.me|oast\.online|oast\.pro|oast\.site|oastify\.com|ptst\.io|r87\.me|requestbin\.net Process initiated by = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe , cgo name = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe , os parent name = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Exploit Public-Facing Application (T1190)- Preventable:
- No
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Outlook creates an executable file on disk Informational Dropper
Common weaponized Office document behavior, as Outlook should not create binary files at all.
Indicator:File file name = *.exe , *.scr , *.dll , *.sys , *.msi AND file path != *\AppData\Local\assembly\tmp\*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\MSIP.Office.*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\SIP.Office.*.DLL AND *\AppData\Local\Temp\*.DLL AND *:\TEMP\*\IntResource64.dll AND action type = create Process initiated by = outlook.exe
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
SunBurst Module loaded High Infiltration
Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe.
Indicator:Image Load module sha256 = 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 , dab758bf98d9b36fa057a66cd0284737abf89857b73ca89280267ee7caf62f3b , eb6fab5a2964c5817fb239a7a5079cabca0a00464fb3e07155f28b0a57a2c0ed , c09040d35630d75dfef0f804f320f8b3d16a481071076918e9b236a321c1ea77 , ac1b2b89e60707a20e9eb1ca480bc3410ead40643b386d624c5d21b47c02917c , 019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134 , ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 , a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc , D3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af Process initiated by = *businesslayerhost* , cgo name = *businesslayerhost* , os parent name = *businesslayerhost* Host host os = windows
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Supply Chain Compromise (T1195) Application Layer Protocol (T1071)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Web server process drops an executable to disk Informational Dropper
Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application.
Indicator:File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND action type = create Process initiated by = w3wp.exe , httpd.exe , nginx.exe , php-cgi.exe , initiated by = *apache* , *tomcat*
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Exploit Public-Facing Application (T1190)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Web server spawns an unsigned process Informational Infiltration
Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application.
Indicator:Process action type = execution AND process execution signature = Unsigned , Invalid Signature , N/A Process initiated by = w3wp.exe , httpd.exe , nginx.exe , php-cgi.exe , initiated by = *apache* , *tomcat* Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Exploit Public-Facing Application (T1190)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23