BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
6 BIOCs match the current filters. technique: T1566 ✕
Download CSV Show ATT&CK heatmapAdobe Acrobat Reader drops an executable file to disk Informational Dropper
The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt.
Indicator:File file name = *.exe , *.scr , *.dll , *.sys , *.com , *.bin , *.msi AND file path != *adobe\acrobat\*usercache.bin AND action type = create Process initiated by = acrord32.exe AND initiator signature = Signed AND initiator signer = *adobe systems* Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Adobe reader spawns a browser Informational Dropper
If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts.
Indicator:Process action type = execution AND target process name = iexplore.exe , chrome.exe , firefox.exe , opera.exe , microsoftedge.exe , microsoftedgecp.exe , safari.exe Process initiated by = acrord32.exe , cgo name = acrord32.exe AND initiator signer = *adobe systems* , cgo signer = *adobe systems* AND initiator signature = Signed , cgo signature = Signed Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Excel Web Query file created on disk Informational Infiltration
Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads.
Indicator:File file name = *.iqy AND action type = create
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Office document embeds a .LNK file Informational Execution
An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file.
Indicator:Process action type = execution AND target process cmd = *{00021401-0000-0000-C000-000000000046}* Process initiated by = winword.exe , excel.exe , powerpnt.exe Host host os = windows
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Office process spawns verclsid.exe Informational Execution
A Microsoft Office process launching verclsid.exe may be a sign of phishing.
Indicator:Process action type = execution AND target process name = verclsid.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Outlook creates an executable file on disk Informational Dropper
Common weaponized Office document behavior, as Outlook should not create binary files at all.
Indicator:File file name = *.exe , *.scr , *.dll , *.sys , *.msi AND file path != *\AppData\Local\assembly\tmp\*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\MSIP.Office.*.DLL AND *\AppData\Roaming\Microsoft\UProof\CMA*.bin AND *\AppData\Roaming\Microsoft\UProof\SIP.Office.*.DLL AND *\AppData\Local\Temp\*.DLL AND *:\TEMP\*\IntResource64.dll AND action type = create Process initiated by = outlook.exe
ATT&CK tactics: Initial Access (TA0001)ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11