BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

2 BIOCs match the current filters. technique: T1040 ✕

Download CSV Show ATT&CK heatmap
  • Network Packet Capture: tshark/tcpdump Informational Discovery

    Network packet capture using tshark\tcpdump utility.

    Indicator:

    Process action type = execution AND target process name = tcpdump , tshark Host host os = linux

    ATT&CK tactics: Discovery (TA0007)
    ATT&CK techniques: Network Sniffing (T1040)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Potential Network Sniffing Informational Credential Access

    Network sniffing related processes were detected.

    Indicator:

    Process action type = execution AND target process name = wireshark , tcpdump

    ATT&CK tactics: Credential Access (TA0006) Discovery (TA0007)
    ATT&CK techniques: Network Sniffing (T1040)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11