BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
3 BIOCs match the current filters. tactic: TA0042 ✕ technique: T1204 ✕
Download CSV Show ATT&CK heatmapSimulation activity by AttackIQ Informational Execution
Simulation activity performed by AttackIQ agent.
Indicator:File action type = all Process initiator cmd = *AttackIQ*attack_graph.py*
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Simulation activity by Cymulate Informational Execution
Simulation activity performed by Cymulate agent.
Indicator:File action type = all Process initiator cmd =~ .*(\\ProgramData\\Cymulate\\Agent\\Temp\\cfd_|\\Cymulate\\EDR_Attacks\\).* AND initiated by =~ (cfd|CymulateEDRScenarioExecutor)\.exe
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Simulation activity by SafeBreach Informational Execution
Simulation activity performed by a SafeBreach agent.
Indicator:File action type = all Process initiated by = sbsimulation_sb_*.exe
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23