Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

9 detectors match the current filters. tactic: TA0001 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics BIOC Rare MS-Update Server was detected The endpoint requested an MS-Update operation from a rare update server. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access
Analytics BIOC Suspicious failed HTTP request - potential Spring4Shell exploit A potentially malicious failed HTTP request was received, possibly as part of a Spring4Shell exploitation attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC Suspicious HTTP parameters detected The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access, Persistence
Analytics BIOC Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access