Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

52 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A disabled user attempted to log in A disabled user attempted to log in. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics A user authenticated with weak NTLM to multiple hosts A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. Informational Identity Analytics XDR Agent Credential Access, Resource Development
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Interactive login by a machine account A machine account performed an interactive or remote interactive login. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Informational Identity Analytics XDR Agent Initial Access
Analytics Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics BIOC Linux local user account creation A user executed a process associated with user account creation. Informational Identity Analytics XDR Agent Persistence
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics XDR Agent Defense Evasion
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics XDR Agent Credential Access
Analytics Multiple users authenticated with weak NTLM to a host Multiple user accounts authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be a result of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible Pass-the-Hash An account was successfully logged on to with new credentials. This login type is rare and may be an attacker's attempt to pass-the-hash and move laterally within a network. Low Identity Analytics XDR Agent Lateral Movement
Analytics Possible TGT reuse from different hosts (pass the ticket) We observed two different hosts sending TGS using the same TGT. This may indicate a TGT was stolen and passed to another host. Informational Identity Analytics XDR Agent Lateral Movement
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics BIOC Rare LOLBIN Process Execution by User A user executed a living-off-the-land binary (LOLBIN) process that is unusual for this user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare NTLM Access By User To Host An unusual NTLM authentication attempt by a user to a host. This may indicate the use of stolen credentials or access tokens to access restricted hosts. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Rare NTLM Usage by User Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
Analytics SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Suspicious NTLM authentication with machine account A suspicious NTLM authentication attempt was made by a machine account. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement