Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

364 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Kerberos Traffic from Non-Standard Process The endpoint had a non-standard process communicating over ports normally used by Kerberos. An attacker might be using malicious tools to move laterally. Medium Platform Analytics XDR Agent Discovery
Analytics BIOC Keylogging using system commands Usage of a Linux system utility to capture input. Low Platform Analytics XDR Agent Credential Access, Collection
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. Medium Platform Analytics XDR Agent Execution, Discovery
Analytics Large Upload (FTP) The endpoint transferred an excessively large amounts of data to a single destination over FTP. Cortex XDR Analytics assumes endpoint traffic towards a specific destination should be about the same over long periods of time. For that reason, Cortex XDR detected this abnormal behavior of a large data upload. An attacker may be exfiltrating data directly to the internet using this protocol. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (Generic) The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC LOLBAS executable injects into another process A signed binary, which can be abused to run code, injected code to another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC LOLBIN process executed with a high integrity level A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. Low Platform Analytics XDR Agent Privilege Escalation
Analytics Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Manipulation of netsh helper DLLs Registry keys Registering netsh helper DLLs is uncommon, and could be used by malware for persistence. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Masquerading as the Linux crond process Copies a file and renames it as crond. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Microsoft Office injects code into a process An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways. Low Platform Analytics XDR Agent Initial Access, Defense Evasion
Analytics BIOC Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
Analytics BIOC Mount command was executed from within a Kubernetes pod to list all the attached filesystems The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC MpCmdRun.exe was used to download files into the system Attackers might be using legitimate Windows Defender executables to download malicious code onto the system. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Mshta.exe launched with suspicious arguments Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Mshta.exe spawns from a browser process Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC MSI accessed a web page running a server-side script The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Msiexec execution of an executable from an uncommon remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Informational Platform Analytics XDR Agent Defense Evasion
Analytics Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Multiple uncommon SSH Servers with the same Server host key Multiple uncommon SSH servers were observed using the same host key. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. High Platform Analytics XDR Agent Command and Control
Analytics BIOC New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. Low Platform Analytics XDR Agent Defense Evasion
Analytics New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Office process spawned with suspicious command-line arguments An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Phantom DLL Loading An attacker might leverage existing processes missing module loads to load malicious code into trusted processes. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Ping to localhost from an uncommon, unsigned parent process Ping is often used by malware and attackers to delay the execution of suspicious commands in sandbox environments. Informational Platform Analytics XDR Agent Defense Evasion
Analytics Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics BIOC Possible binary padding using dd A suspicious dd command ran and added data to a binary. This may indicate binary padding to change the hash of a file. Informational Platform Analytics XDR Agent Defense Evasion
Analytics Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. Informational Platform Analytics XDR Agent Credential Access
Analytics Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. Medium Platform Analytics XDR Agent Collection
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Possible data obfuscation A command that can be used for file obfuscation was executed with an uncommon command line. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. Low Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. Informational Platform Analytics XDR Agent Collection
Analytics BIOC Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Possible Kerberoasting without SPNs A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. Low Platform Analytics Windows Event Collector, XDR Agent Privilege Escalation
Analytics BIOC Possible malicious .NET compilation started by a commonly abused process Attackers may use csc.exe to compile payloads on a compromised machine. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible network service discovery via command-line tool An attacker may use command-line utilities to discover open ports and services on a remote host. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics BIOC Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible path traversal via HTTP request The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Discovery
Analytics BIOC Possible RDP session hijacking using tscon.exe The executable tscon.exe can be used to hijack other sessions on the same computer. The attacker may use another user's credentials to proceed with the lateral movement or disguise the activity. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible use of IPFS was detected The host produced traffic consistent with IPFS. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. Medium Platform Analytics XDR Agent Defense Evasion, Credential Access
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. Informational Platform Analytics XDR Agent Exfiltration
Analytics Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics Rare access to known advertising domains The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Persistence
Analytics BIOC Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare binary connected to a rare cloud resource Rare binary connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare binary connected to a rare external host Rare binary connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare communication over email ports to external email server by unsigned process These methods are used by malware and attackers to leak data and remain undetected. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare file transfer over SMB protocol The endpoint performed an abnormal file transfer over SMB to a remote host. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare security product signed executable executed in the network Attackers may attempt to install a security product with a known vulnerability to bypass security features. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics BIOC Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Rare unsigned process execution by scheduled task Rare and unsigned process was executed by a scheduled task. Low Platform Analytics XDR Agent Persistence