Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
12 detectors match the current filters. tactic: TA0008 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Rare NTLM Usage by User Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM. | Informational | Identity Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Suspicious Encrypting File System Remote call (EFSRPC) to domain controller An Encrypting File System Remote call (EFSRPC) was made to a domain controller. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |
| Analytics BIOC | Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Lateral Movement |