Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
5 detectors match the current filters. tactic: TA0008 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Rare NTLM Usage by User Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM. | Informational | Identity Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |