BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

2 BIOCs match the current filters. technique: T1491 ✕

Download CSV Show ATT&CK heatmap
  • Internet Explorer home page modification Low Tampering

    The Internet Explorer home page could be changed to a malicious page.

    Indicator:

    Registry action type = all AND registry key name = *\Software\Microsoft\Internet Explorer\Main\* AND registry value name = *Start Page* Process initiated by != iexplore.exe AND cgo name != iexplore.exe Host host os = windows

    ATT&CK tactics: Impact (TA0040) Credential Access (TA0006)
    ATT&CK techniques: Defacement (T1491) Input Capture: GUI Input Capture (T1056.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Process changes the Windows logon text Medium Tampering

    This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user.

    Indicator:

    Registry action type = create_registry_key , set_registry_value , rename_registry_key AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\LegalNoticeCaption* Host host os = windows

    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Defacement (T1491)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11