BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
7 BIOCs match the current filters. technique: T1204 ✕
Download CSV Show ATT&CK heatmapMicrosoft Office process spawns a commonly abused process Informational Execution
Common weaponized office document behavior.
Indicator:Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , rundll32.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe AND target process cmd != *\spool\DRIVERS* AND *C:\Windows\system32\shell32.dll,OpenAs_RunDLL* AND *ServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793}* Process initiated by = outlook.exe , excel.exe , winword.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Microsoft Office process spawns an unsigned process Informational Execution
Common weaponized office document behavior.
Indicator:Process action type = execution AND process execution signature = Unsigned , Invalid Signature , N/A , Weak Hash Process initiated by = outlook.exe , excel.exe , winword.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe Host host os = windows
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Office process writes an executable file to disk Informational Execution
An executable file was written by a Microsoft Office application to disk.
Indicator:File file name = *.exe , *.bat , *.ps1 , *.sys , *.dll , *.vb , *.vbs AND action type = create Process initiated by = winword.exe , excel.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Process runs with a double extension Medium File Type Obfuscation
Look for executables with a common double extension. These are often used to disguise malware as some form of user content.
Indicator:Process action type = execution AND target process name = *.docx.exe , *.xlsx.exe , *.pptx.exe , *.pdf.exe , *.wav.exe , *.mp3.exe , *.mkv.exe , *.avi.exe , *.mp4.exe , *.gif.exe , *.bmp.exe , *.png.exe , *.jpg.exe , *.jpeg.exe , *.m4a.exe , *.html.exe , *.htm.exe , *.mht.exe , *.doc.exe , *.xls.exe , *.ppt.exe Process cgo name != NewWorld.Services.MobileServer.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: User Execution (T1204)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Simulation activity by AttackIQ Informational Execution
Simulation activity performed by AttackIQ agent.
Indicator:File action type = all Process initiator cmd = *AttackIQ*attack_graph.py*
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Simulation activity by Cymulate Informational Execution
Simulation activity performed by Cymulate agent.
Indicator:File action type = all Process initiator cmd =~ .*(\\ProgramData\\Cymulate\\Agent\\Temp\\cfd_|\\Cymulate\\EDR_Attacks\\).* AND initiated by =~ (cfd|CymulateEDRScenarioExecutor)\.exe
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Simulation activity by SafeBreach Informational Execution
Simulation activity performed by a SafeBreach agent.
Indicator:File action type = all Process initiated by = sbsimulation_sb_*.exe
ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23