BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0009 ✕ technique: T1123 ✕
Download CSV Show ATT&CK heatmapBuilt-in SoundRecorder tool capturing audio Informational Collection
SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user.
Indicator:Process action type = execution AND os actor process signature vendor != Zscaler, Inc. AND JAL Information Technology Co.,Ltd. AND LIGHTSPEED SYSTEMS, INC. AND Ivanti, Inc. AND Lightspeed Systems (Lightspeed Solutions, LLC.) AND target process cmd = *soundrecorder* Process initiated by != sihost.exe AND svchost.exe AND explorer.exe AND nssm.exe AND cgo name != sihost.exe AND svchost.exe AND explorer.exe AND nssm.exe AND os parent name != sihost.exe AND svchost.exe AND explorer.exe AND nssm.exe AND initiator signature = Unsigned , Signed , Invalid Signature , Weak Hash , cgo signature = Unsigned , Signed , Invalid Signature , Weak Hash , os parent signature = Unsigned , Signed , Invalid Signature , Weak Hash AND initiator signer != Zscaler, Inc. AND JAL Information Technology Co.,Ltd. AND LIGHTSPEED SYSTEMS, INC. AND Ivanti, Inc. AND Lightspeed Systems (Lightspeed Solutions, LLC.) AND cgo signer != Zscaler, Inc. AND JAL Information Technology Co.,Ltd. AND LIGHTSPEED SYSTEMS, INC. AND Ivanti, Inc. AND Lightspeed Systems (Lightspeed Solutions, LLC.) Host host os != linux
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Audio Capture (T1123)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Collecting audio via PowerShell command Low Collection
An attacker may collect audio from the microphone using PowerShell.
Indicator:Process action type = execution AND target process cmd = *Get-DefaultAudioDevice* , *Get-AudioDeviceList* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDevice* , *Set-DefaultAudioDeviceVolume* , *Get-DefaultAudioDeviceVolume* , *Set-DefaultAudioDeviceMute* , *Write-DefaultAudioDeviceValue* AND target process name = powershell.exe
ATT&CK tactics: Collection (TA0009)ATT&CK techniques: Audio Capture (T1123)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23