Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
4 detectors match the current filters. tactic: TA0010 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics | Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics | Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |