BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • Manipulation of the sticky keys file Medium Privilege Escalation

    Possible login bypass attack.

    Indicator:

    File action type = create , write AND file path = *:\Windows\System32 , *:\Windows\Syswow64 AND file name = sethc.exe

    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Event Triggered Execution: Accessibility Features (T1546.008)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Shim database file access Informational Persistence

    An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence.

    Indicator:

    File action type = create , rename , write AND file path = *\windows\apppatch\custom\*

    ATT&CK tactics: Persistence (TA0003) Privilege Escalation (TA0004)
    ATT&CK techniques: Event Triggered Execution: Application Shimming (T1546.011)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23