Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0008 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Suspicious Encrypting File System Remote call (EFSRPC) to domain controller An Encrypting File System Remote call (EFSRPC) was made to a domain controller. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Lateral Movement, Defense Evasion
Analytics BIOC Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Lateral Movement