Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
19 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics BIOC | Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics | Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics BIOC | Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access, Lateral Movement |
| Analytics | Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls | Discovery |
| Analytics | Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Unusual SSH Activity Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control |
| Analytics BIOC | Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |