BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
5 BIOCs match the current filters. tactic: TA0007 ✕ technique: T1046 ✕
Download CSV Show ATT&CK heatmapEnumeration of Windows services from public IP addresses Informational Discovery
Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits.
Indicator:Network Connections Source Local IP != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND 239.* Destination Remote Port = 445 , 139 , 135 , 138 , 137 AND app id contains *,ms-* AND protocol = tcp
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Remote System Discovery (T1018) Account Discovery (T1087) Network Service Discovery (T1046)- Preventable:
- No
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Execution of Fsociety tool pack Medium Discovery
The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more.
Indicator:Process action type = execution AND target process cmd = *fsociety.py* , target process name = fsociety Host host os = linux
ATT&CK tactics: Discovery (TA0007) Credential Access (TA0006)ATT&CK techniques: Network Service Discovery (T1046) Brute Force (T1110)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Installation of networking security tools Informational Discovery
A security or penetration testing tool such as wireshark and nmap is being installed.
Indicator:Process action type = execution AND target process name = *Wireshark-* , *WiresharkPortable* , *WinPcap_* , *nmap*setup* , *NPFInstall.exe*
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Network Service Discovery (T1046)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Possible Oracle enumeration via tnscmd10g Low Discovery
The tnscmd10g command-line utility was executed, allowing the enumeration of Oracle DBs.
Indicator:Process action type = execution AND target process name = tnscmd10g* Host host os = linux
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Network Service Discovery (T1046)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
UDP protocol scanner execution Low Discovery
The UDP Protocol Scanner performs UDP service discovery. Attackers may use it to enumerate UDP services in their target's environment.
Indicator:Process action type = execution AND target process cmd = *udp-proto-scanner.pl* Host host os = linux
ATT&CK tactics: Discovery (TA0007)ATT&CK techniques: Network Service Discovery (T1046)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23