BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0006 ✕ technique: T1110 ✕
Download CSV Show ATT&CK heatmapExecution of Fsociety tool pack Medium Discovery
The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more.
Indicator:Process action type = execution AND target process cmd = *fsociety.py* , target process name = fsociety Host host os = linux
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)ATT&CK techniques: Network Service Discovery (T1046) Brute Force (T1110)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Kerberos brute-force attack using Kerbrute Informational Credential Access
This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks.
Indicator:Process action type = execution AND target process cmd = *kerbrute* -domain * -users * -passwords * , *kerbrute* -domain * -passwords * -users * , *kerbrute* -users * -domain * -passwords * , *kerbrute* -users * -passwords * -domain * , *kerbrute* -passwords * -users * -domain * , *kerbrute* -passwords * -domain * -users * , *passwordspray * , *bruteforce * , *bruteuser *
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Brute Force (T1110)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11