Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

24 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. Informational Identity Analytics XDR Agent Credential Access, Resource Development
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
Analytics NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. Informational Platform Analytics XDR Agent Credential Access
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC Suspicious NTLM authentication with machine account A suspicious NTLM authentication attempt was made by a machine account. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Uncommon SQL like command line Uncommon SQL query in command line of an executed process. Informational Platform Analytics XDR Agent Credential Access
Analytics Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics BIOC Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. Informational Cortex Cloud XDR Agent Credential Access
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence