Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

2 detectors match the current filters. tactic: TA0006 ✕ technique: T1003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion