BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

7 BIOCs match the current filters. technique: T1204 ✕

Download CSV Show ATT&CK heatmap
  • Microsoft Office process spawns a commonly abused process Informational Execution

    Common weaponized office document behavior.

    Indicator:

    Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , rundll32.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe AND target process cmd != *\spool\DRIVERS* AND *C:\Windows\system32\shell32.dll,OpenAs_RunDLL* AND *ServerRunDll {3eef301f-b596-4c0b-bd92-013beafce793}* Process initiated by = outlook.exe , excel.exe , winword.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Microsoft Office process spawns an unsigned process Informational Execution

    Common weaponized office document behavior.

    Indicator:

    Process action type = execution AND process execution signature = Unsigned , Invalid Signature , N/A , Weak Hash Process initiated by = outlook.exe , excel.exe , winword.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe Host host os = windows

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Office process writes an executable file to disk Informational Execution

    An executable file was written by a Microsoft Office application to disk.

    Indicator:

    File file name = *.exe , *.bat , *.ps1 , *.sys , *.dll , *.vb , *.vbs AND action type = create Process initiated by = winword.exe , excel.exe , powerpnt.exe , visio.exe , winproj.exe , onenote.exe , msaccess.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Process runs with a double extension Medium File Type Obfuscation

    Look for executables with a common double extension. These are often used to disguise malware as some form of user content.

    Indicator:

    Process action type = execution AND target process name = *.docx.exe , *.xlsx.exe , *.pptx.exe , *.pdf.exe , *.wav.exe , *.mp3.exe , *.mkv.exe , *.avi.exe , *.mp4.exe , *.gif.exe , *.bmp.exe , *.png.exe , *.jpg.exe , *.jpeg.exe , *.m4a.exe , *.html.exe , *.htm.exe , *.mht.exe , *.doc.exe , *.xls.exe , *.ppt.exe Process cgo name != NewWorld.Services.MobileServer.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: User Execution (T1204)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Simulation activity by AttackIQ Informational Execution

    Simulation activity performed by AttackIQ agent.

    Indicator:

    File action type = all Process initiator cmd = *AttackIQ*attack_graph.py*

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Simulation activity by Cymulate Informational Execution

    Simulation activity performed by Cymulate agent.

    Indicator:

    File action type = all Process initiator cmd =~ .*(\\ProgramData\\Cymulate\\Agent\\Temp\\cfd_|\\Cymulate\\EDR_Attacks\\).* AND initiated by =~ (cfd|CymulateEDRScenarioExecutor)\.exe

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Simulation activity by SafeBreach Informational Execution

    Simulation activity performed by a SafeBreach agent.

    Indicator:

    File action type = all Process initiated by = sbsimulation_sb_*.exe

    ATT&CK tactics: Execution (TA0002) Resource Development (TA0042)
    ATT&CK techniques: User Execution (T1204) Obtain Capabilities: Tool (T1588.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23