Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

431 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious curl user agent Suspicious user agent provided to curl command. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. Low Platform Analytics XDR Agent Impact, Defense Evasion
Analytics BIOC Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. Low Platform Analytics XDR Agent Defense Evasion
Analytics Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Suspicious failed HTTP request - potential Spring4Shell exploit A potentially malicious failed HTTP request was received, possibly as part of a Spring4Shell exploitation attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC Suspicious HTTP parameters detected The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access, Persistence
Analytics BIOC Suspicious ICMP packet An ICMP router advertisement was sent by a host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. Low Platform Analytics XDR Agent Impact
Analytics BIOC Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration
Analytics BIOC Suspicious NTLM authentication with machine account A suspicious NTLM authentication attempt was made by a machine account. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious PowerShell Enumeration of Running Processes Attackers often enumerate running processes to find and disable security tools. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious print processor registered The endpoint registered a new print processor, which may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. Informational Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Suspicious process execution from tmp folder An unpopular process was executed from the tmp folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious Process Spawned by Adobe Reader Unusual process spawned by Adobe Reader with an uncommon command line. Low Platform Analytics XDR Agent Initial Access
Analytics BIOC Suspicious Process Spawned by wininit.exe An unusual process was spawned by wininit.exe, possibly indicating malicious local or remote code execution. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Suspicious proxy environment variable setting Suspicious proxy environment variable change or definition with a rare command line. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Suspicious RunOnce Parent Process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user login events. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious runonce.exe parent process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user logon events. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Suspicious setspn.exe execution A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast". Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Suspicious SMB connection from domain controller A domain controller has initiated an SMB connection to another host. The domain controllers usually communicate over SMB only with other domain controllers. An attacker can abuse such sessions for relay attacks. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious time provider registered The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious usage of File Server Remote VSS Protocol (FSRVP) A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done. High Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. Low Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC System information discovery via psinfo.exe Using psinfo.exe, the attacker can gather information about the network, and gain an in-depth understanding of which devices are relevant to attack. Low Platform Analytics XDR Agent Discovery
Analytics BIOC System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC The CA policy EditFlags was queried The CA policy EditFlags was queried. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC The Linux system firewall was disabled The system firewall was disabled. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. Low Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. High Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon ARP cache listing via arp.exe The arp.exe command is used to display and modify entries in the Address Resolution Protocol (ARP) cache. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. Informational Cortex Cloud XDR Agent Execution
Analytics BIOC Uncommon communication to an instant messaging server A rare communication between a process to a known instant messaging server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). Medium Platform Analytics XDR Agent Execution, Defense Evasion, Privilege Escalation
Analytics BIOC Uncommon DotNet module load relationship A signed process that usually doesn't use DotNet loaded a common DotNet module. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon IP Configuration Listing via ipconfig.exe The 'ipconfig' command is used to display TCP/IP network configuration information and refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Adversaries may use the command to discover network configuration details. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon kernel module load Loading of a kernel module using the modprobe command. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon Launch Agent persistency was registered or modified An uncommon Launch Agent persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon Launch Daemon persistency was registered or modified An uncommon Launch Daemon persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon Linux process communication to a rare external host An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon local scheduled task creation via schtasks.exe The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon login item persistency was registered or modified An uncommon login item persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon macOS process communication to a rare external host An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon Managed Object Format (MOF) compiler usage The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon routing table listing via route.exe The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Uncommon signed process execution by scheduled task An uncommon process was executed by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon SQL like command line Uncommon SQL query in command line of an executed process. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Uncommon SSH session was established An uncommon SSH session was established. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. High Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unpopular rsync process execution An unpopular rsync process was executed on the host. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. Medium Platform Analytics XDR Agent Defense Evasion, Privilege Escalation
Analytics BIOC Untrusted process contacted LLM API An untrusted process contacted an LLM API. Informational Platform Analytics XDR Agent Resource Development