BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • Fontdrvhost.exe makes network connections Informational Execution

    A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation.

    Indicator:

    Network action type = incoming , outgoing , failed Process initiated by = fontdrvhost.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Exploitation for Client Execution (T1203)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Microsoft Office Equation Editor spawns a commonly abused process Medium Execution

    A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. CVE-2017-11882 Microsoft Office Memory Corruption Vulnerability.

    Indicator:

    Process action type = execution AND target process name = cmd.exe , powershell.exe , mshta.exe , wscript.exe , cscript.exe , regsvr32.exe Process initiated by = EQNEDT32.EXE , cgo name = EQNEDT32.EXE

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Exploitation for Client Execution (T1203)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Unusual process spawned by fontdrvhost.exe Informational Execution

    A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation.

    Indicator:

    Process action type = execution AND target process name != werfault.exe AND winlogon.exe AND wininit.exe AND csrss.exe AND fontdrvhost.exe Process initiated by = fontdrvhost.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: Exploitation for Client Execution (T1203)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11