Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

431 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. Informational Identity Threat Detection (ITDR) XDR Agent Defense Evasion
Analytics BIOC A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. Informational Platform Analytics XDR Agent Exfiltration
Analytics A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. Informational Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics A compromised process accessed a rare external host A compromised process accessed a rare external host. Low Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics BIOC A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC A disabled user attempted to log in A disabled user attempted to log in. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Impact
Analytics BIOC A process connected to a rare cloud resource A process connected to a rare cloud resource. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC A process connected to a rare external host A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process connected to rare external host A process connected to a rare external host. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A process was executed with a command line obfuscated by Unicode character substitution A process was executed with a command line obfuscated by Unicode character substitution. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. Informational Platform Analytics XDR Agent Impact
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Analytics BIOC A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics BIOC A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. Informational Identity Threat Detection (ITDR) Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics A user accessed multiple time-consuming websites A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics A user authenticated with weak NTLM to multiple hosts A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. Informational Identity Analytics XDR Agent Credential Access, Resource Development
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal process connection to default Meterpreter port This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. Informational Platform Analytics XDR Agent Command and Control
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal SMB scanning activity to multiple hosts An endpoint performed a new, unfamiliar SMB scanning activity to multiple hosts on the network. Informational Platform Analytics XDR Agent Reconnaissance
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics BIOC Adding execution privileges A script was granted execution privileges using chmod before being run. Informational Platform Analytics XDR Agent Execution
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics BIOC An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. Medium Platform Analytics XDR Agent Persistence, Defense Evasion
Analytics BIOC Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. Informational Platform Analytics Palo Alto Networks Firewall threat Logs, XDR Agent Reconnaissance
Analytics BIOC AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. Medium Platform Analytics XDR Agent Persistence
Analytics Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics BIOC Certutil pfx parsing Certutil was used to parse a pfx certificate file. Low Platform Analytics XDR Agent Collection
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command execution via wmiexec Attackers may use WMI to execute commands on the target host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Compressing data using python Usage of a Python module to compress files. Low Platform Analytics XDR Agent Collection
Analytics BIOC Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. Low Platform Analytics XDR Agent Execution
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent Discovery
Analytics DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Download a script using the python requests module Download a shell script from a remote location using the Python requests module. Low Platform Analytics XDR Agent Execution
Analytics Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
Analytics BIOC Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of an uncommon process at an early startup stage Uncommon execution of an executable found in an early startup stage. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process at an early startup stage by Windows system binary Uncommon execution of an executable found in an early startup stage by Windows system binary. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process with a local/domain user SID at an early startup stage Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of command from within a Kubernetes pod using kubelet credentials A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Execution of dllhost.exe with an empty command line The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. Informational Platform Analytics XDR Agent Defense Evasion
Analytics External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. Low Platform Analytics XDR Agent Credential Access
Analytics Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics Failed DNS The endpoint is performing DNS lookups that are failing at an excessively high rate when compared to its peer group. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Globally uncommon high entropy module was loaded A module with high entropy and a globally uncommon hash was loaded. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon high entropy process was executed A process with high entropy and a globally uncommon hash was executed. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon image load from a signed process A signed process loaded a DLL that, on a global level, it usually doesn't load. Informational Platform Analytics XDR Agent Defense Evasion