Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
68 detectors match the current filters. tactic: TA0002 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Adding execution privileges A script was granted execution privileges using chmod before being run. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command execution via wmiexec Attackers may use WMI to execute commands on the target host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. | Medium | Platform Analytics | XDR Agent | Exfiltration, Execution |
| Analytics BIOC | Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Download a script using the python requests module Download a shell script from a remote location using the Python requests module. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Interactive at.exe privilege escalation method Detects an interactive AT scheduled task, which may be used as a form of privilege escalation. | Low | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. | Medium | Platform Analytics | XDR Agent | Execution, Discovery |
| Analytics BIOC | Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PsExec was executed with a suspicious command line PsExec.exe was executed. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. | Low | Platform Analytics | XDR Agent | Execution, Persistence, Privilege Escalation |
| Analytics BIOC | Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. | Low | Platform Analytics | XDR Agent | Execution, Persistence, Privilege Escalation |
| Analytics BIOC | Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. | Low | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. | Medium | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. | Informational | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. | Low | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. | Low | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. | Low | Platform Analytics | XDR Agent | Execution, Exfiltration |
| Analytics BIOC | Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion, Privilege Escalation |
| Analytics BIOC | Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution, Lateral Movement |
| Analytics BIOC | Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |