Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

13 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics XDR Agent Credential Access
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics BIOC Possible Pass-the-Hash An account was successfully logged on to with new credentials. This login type is rare and may be an attacker's attempt to pass-the-hash and move laterally within a network. Low Identity Analytics XDR Agent Lateral Movement
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion