BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
1 BIOC match the current filters. tactic: TA0011 ✕ technique: T1102 ✕
Download CSV Show ATT&CK heatmapNon-browser process downloads content from GitHub Informational Evasion
Check for possible attempts to use GitHub as a malicious payload deployment mechanism. This technique is known to be used frequently by threat actors to serve malicious scripts/payloads.
Indicator:Network action type = outgoing , failed AND remote host = *githubusercontent.com* , *github.com , *gitlab.com Process initiated by != iexplore.exe AND chrome.exe AND firefox.exe AND opera.exe AND msedge.exe AND microsoftedge.exe AND microsoftedgecp.exe AND brave.exe AND vivaldi.exe AND chrome AND google chrome helper AND chromium AND firefox AND opera AND safari AND brave AND vivaldi AND initiated by != microsoft edge* AND git* AND grafana-server* AND initiator path != *\microsoft vs code\code.exe AND /Applications/Visual Studio Code.app/* AND *Sisense*java.exe* AND cgo cmd != *puppetlabs* AND *TeamCity\bin*
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Web Service (T1102)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23