Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

4 detectors match the current filters. tactic: TA0004 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
Analytics BIOC TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics XDR Agent Privilege Escalation, Persistence