BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • BitTorrent P2P file sharing Informational Exfiltration

    The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information.

    Indicator:

    Network Connections app id contains *bittorrent*

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    No
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Bitsadmin.exe used to upload data High Exfiltration

    Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools.

    Indicator:

    Process action type = execution AND target process cmd = */transfer * AND */upload * AND target process name = bitsadmin.exe

    ATT&CK tactics: Exfiltration (TA0010) Defense Evasion (TA0005)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048) BITS Jobs (T1197)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Curl connects to an external network Informational Exfiltration

    Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization.

    Indicator:

    Network action type = outgoing , failed AND remote ip != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND remote port != 53 AND 0 Process initiated by = curl AND cgo signer != *palo alto networks* Host host os = linux , windows

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • FTP/SSH client reads office files Low Exfiltration

    Seeing FTP/SSH related software accessing office files could be an indication of data exfiltration.

    Indicator:

    File file name = *.docx , *.doc , *.xlsx , *.xls , *.ppt , *.pptx AND action type = read Process initiated by = ftp.exe , putty.exe , winscp.exe , plink.exe , bash.exe , scp.exe , pscp.exe , psftp.exe

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Microsoft Office spawns curl/wget on a macOS device Informational Exfiltration

    Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device.

    Indicator:

    Process action type = execution AND target process name = curl , wget Process initiated by = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook , cgo name = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook , os parent name = Microsoft Excel , Microsoft Word , Microsoft PowerPoint , Microsoft Outlook

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol (T1048.003)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Scripting engine makes connections over DNS ports Informational Exfiltration

    Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.

    Indicator:

    Network action type = failed , outgoing AND remote port = 53 Process os parent name = cmd.exe , powershell.exe , wscript.exe , cscript.exe , mshta.exe AND os parent signature = Signed Host host os != linux AND host os = windows

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Unsigned process makes connections over DNS ports Informational Exfiltration

    An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection.

    Indicator:

    Network action type = outgoing , failed AND remote port = 53 Process os parent signature = Unsigned , N/A , Weak Hash , Invalid Signature Host host os = windows

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Wget connection to an external network Informational Exfiltration

    Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization.

    Indicator:

    Network action type = outgoing , failed AND remote ip != 10.* AND 172.16.* AND 172.17.* AND 172.18.* AND 172.19.* AND 172.20.* AND 172.21.* AND 172.22.* AND 172.23.* AND 172.24.* AND 172.25.* AND 172.26.* AND 172.27.* AND 172.28.* AND 172.29.* AND 172.30.* AND 172.31.* AND 192.168.* AND 127.* AND 169.254.* AND remote port != 53 AND 0 Process initiated by = wget

    ATT&CK tactics: Exfiltration (TA0010)
    ATT&CK techniques: Exfiltration Over Alternative Protocol (T1048)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23