Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
14 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A disabled user attempted to log in A disabled user attempted to log in. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access |
| Analytics BIOC | Interactive login by a machine account A machine account performed an interactive or remote interactive login. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. | Informational | Platform Analytics | XDR Agent | Initial Access, Lateral Movement |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |