BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0001 ✕ technique: T1071 ✕
Download CSV Show ATT&CK heatmapExchange process writing aspx files High Infiltration
An exchange process is writing to .aspx files. This may be an actor dropping web shells.
Indicator:File action type = create , write AND file path =~ (\\inetpub\\wwwroot\\aspnet_client\\|\\frontend\\httpproxy\\owa\\auth\\|\\frontend\\httpproxy\\ecp\\auth\\).*\.aspx Process initiated by = UMWorkerProcess.exe , w3wp.exe
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Exploit Public-Facing Application (T1190) Application Layer Protocol: Web Protocols (T1071.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
SunBurst Module loaded High Infiltration
Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe.
Indicator:Image Load module sha256 = 32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77 , dab758bf98d9b36fa057a66cd0284737abf89857b73ca89280267ee7caf62f3b , eb6fab5a2964c5817fb239a7a5079cabca0a00464fb3e07155f28b0a57a2c0ed , c09040d35630d75dfef0f804f320f8b3d16a481071076918e9b236a321c1ea77 , ac1b2b89e60707a20e9eb1ca480bc3410ead40643b386d624c5d21b47c02917c , 019085a76ba7126fff22770d71bd901c325fc68ac55aa743327984e89f4b0134 , ce77d116a074dab7a22a0fd4f2c1ab475f16eec42e1ded3c0b0aa8211fe858d6 , a25cadd48d70f6ea0c4a241d99c5241269e6faccb4054e62d16784640f8e53bc , D3c6785e18fba3749fb785bc313cf8346182f532c59172b69adfb31b96a5d0af Process initiated by = *businesslayerhost* , cgo name = *businesslayerhost* , os parent name = *businesslayerhost* Host host os = windows
ATT&CK tactics: Initial Access (TA0001) Command and Control (TA0011)ATT&CK techniques: Supply Chain Compromise (T1195) Application Layer Protocol (T1071)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23