Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon RDP session was established An RDP session was established with uncommon parameters. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics | Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics BIOC | Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution, Lateral Movement |
| Analytics BIOC | Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Discovery |