BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

11 BIOCs match the current filters. tactic: TA0001 ✕

Download CSV Show ATT&CK heatmap
  • Adobe Acrobat Reader drops an executable file to disk Informational Dropper

    The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.

    Indicator:

    File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Adobe reader spawns a browser Informational Dropper

    If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts.

    Indicator:

    Process action type = execution AND target process name = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe Process initiated by = acrord32.exe , cgo name = acrord32.exe AND initiator signer = *adobe systems* , cgo signer = *adobe systems* AND initiator signature = Signed , cgo signature = Signed Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Excel Web Query file created on disk Informational Infiltration

    Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads.

    Indicator:

    File file name = *.iqy AND action type = create

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Exchange process writing aspx files High Infiltration

    An exchange process is writing to .aspx files. This may be an actor dropping web shells.

    Indicator:

    File action type = create , write AND file path =~ (\\inetpub\\wwwroot\\aspnet_client\\|\\frontend\\httpproxy\\owa\\auth\\|\\frontend\\httpproxy\\ecp\\auth\\).*\.aspx Process initiated by = UMWorkerProcess.exe , w3wp.exe

    ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)
    ATT&CK techniques: Exploit Public-Facing Application (T1190) Application Layer Protocol: Web Protocols (T1071.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Office document embeds a .LNK file Informational Execution

    An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file.

    Indicator:

    Process action type = execution AND target process cmd = *{00021401-0000-0000-C000-000000000046}* Process initiated by = winword.exe , excel.exe , powerpnt.exe Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Office process spawns verclsid.exe Informational Execution

    A Microsoft Office process launching verclsid.exe may be a sign of phishing.

    Indicator:

    Process action type = execution AND target process name = verclsid.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Out of band testing domain connection Low Infiltration

    Connection from web service process to out-of-band-testing domain.

    Indicator:

    Network action type = outgoing , failed , raw_packet AND remote host =~ burpcollabat\.net|canarytokens\.com|dnslog\.cn|interact\.sh|interactsh\.com|oast\.fun|oast\.live|oast\.me|oast\.online|oast\.pro|oast\.site|oastify\.com|ptst\.io|r87\.me|requestbin\.net Process initiated by = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe , cgo name = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe , os parent name = apache.exe , apache2.exe , caddy.exe , httpd.exe , jsvc.exe , lighthttpd.exe , lighttpd.exe , lshttpd.exe , nginx.exe , nhttpd.exe , node.exe , php-cgi.exe , php.exe , tomcat.exe , tomcat7.exe , w3wp.exe

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Exploit Public-Facing Application (T1190)
    Preventable:
    No
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Outlook creates an executable file on disk Informational Dropper

    Common weaponized Office document behavior, as Outlook should not create binary files at all.

    Indicator:

    File file name = *.exe , *.scr , *.dll , *.sys , *.msi AND file path != *\AppData\Local\assembly\tmp\*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\MSIP.Office.*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\SIP.Office.*.DLL AND *\AppData\Local\Temp\*.DLL AND *:\TEMP\*\IntResource64.dll AND action type = create Process initiated by = outlook.exe

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • SunBurst Module loaded High Infiltration

    Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe.

    Indicator:

    Image Load module sha256 = 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 , dab758bf98d9b36fa057a66cd0284737abf89857b73ca89280267ee7caf62f3b , eb6fab5a2964c5817fb239a7a5079cabca0a00464fb3e07155f28b0a57a2c0ed , c09040d35630d75dfef0f804f320f8b3d16a481071076918e9b236a321c1ea77 , ac1b2b89e60707a20e9eb1ca480bc3410ead40643b386d624c5d21b47c02917c , 019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134 , ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 , a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc , D3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af Process initiated by = *businesslayerhost* , cgo name = *businesslayerhost* , os parent name = *businesslayerhost* Host host os = windows

    ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)
    ATT&CK techniques: Supply Chain Compromise (T1195) Application Layer Protocol (T1071)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Web server process drops an executable to disk Informational Dropper

    Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application.

    Indicator:

    File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND action type = create Process initiated by = w3wp.exe , httpd.exe , nginx.exe , php-cgi.exe , initiated by = *apache* , *tomcat*

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Exploit Public-Facing Application (T1190)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Web server spawns an unsigned process Informational Infiltration

    Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application.

    Indicator:

    Process action type = execution AND process execution signature = Unsigned , Invalid Signature , N/A Process initiated by = w3wp.exe , httpd.exe , nginx.exe , php-cgi.exe , initiated by = *apache* , *tomcat* Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Exploit Public-Facing Application (T1190)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23