BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
2 BIOCs match the current filters. tactic: TA0040 ✕ technique: T1491 ✕
Download CSV Show ATT&CK heatmapInternet Explorer home page modification Low Tampering
The Internet Explorer home page could be changed to a malicious page.
Indicator:Registry action type = all AND registry key name = *\Software\Microsoft\Internet Explorer\Main\* AND registry value name = *Start Page* Process initiated by != iexplore.exe AND cgo name != iexplore.exe Host host os = windows
ATT&CK tactics: Impact (TA0040) Credential Access (TA0006)ATT&CK techniques: Defacement (T1491) Input Capture: GUI Input Capture (T1056.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Process changes the Windows logon text Medium Tampering
This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user.
Indicator:Registry action type = create_registry_key , set_registry_value , rename_registry_key AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption* Host host os = windows
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Defacement (T1491)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11