Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

23 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics Large Upload (FTP) The endpoint transferred an excessively large amounts of data to a single destination over FTP. Cortex XDR Analytics assumes endpoint traffic towards a specific destination should be about the same over long periods of time. For that reason, Cortex XDR detected this abnormal behavior of a large data upload. An attacker may be exfiltrating data directly to the internet using this protocol. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (Generic) The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics BIOC Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics BIOC Possible Kerberoasting without SPNs A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics BIOC Suspicious SMB connection from domain controller A domain controller has initiated an SMB connection to another host. The domain controllers usually communicate over SMB only with other domain controllers. An attacker can abuse such sessions for relay attacks. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Uncommon SSH session was established An uncommon SSH session was established. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Weakly-Encrypted Kerberos Ticket Requested A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes and is typically a sign of a Kerberoasting attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access