BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

6 BIOCs match the current filters. technique: T1566 ✕

Download CSV Show ATT&CK heatmap
  • Adobe Acrobat Reader drops an executable file to disk Informational Dropper

    The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.

    Indicator:

    File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Adobe reader spawns a browser Informational Dropper

    If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts.

    Indicator:

    Process action type = execution AND target process name = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe Process initiated by = acrord32.exe , cgo name = acrord32.exe AND initiator signer = *adobe systems* , cgo signer = *adobe systems* AND initiator signature = Signed , cgo signature = Signed Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Excel Web Query file created on disk Informational Infiltration

    Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads.

    Indicator:

    File file name = *.iqy AND action type = create

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Office document embeds a .LNK file Informational Execution

    An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file.

    Indicator:

    Process action type = execution AND target process cmd = *{00021401-0000-0000-C000-000000000046}* Process initiated by = winword.exe , excel.exe , powerpnt.exe Host host os = windows

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Office process spawns verclsid.exe Informational Execution

    A Microsoft Office process launching verclsid.exe may be a sign of phishing.

    Indicator:

    Process action type = execution AND target process name = verclsid.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Outlook creates an executable file on disk Informational Dropper

    Common weaponized Office document behavior, as Outlook should not create binary files at all.

    Indicator:

    File file name = *.exe , *.scr , *.dll , *.sys , *.msi AND file path != *\AppData\Local\assembly\tmp\*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\MSIP.Office.*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\SIP.Office.*.DLL AND *\AppData\Local\Temp\*.DLL AND *:\TEMP\*\IntResource64.dll AND action type = create Process initiated by = outlook.exe

    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11