Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1110 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. | Informational | Identity Analytics | XDR Agent | Credential Access, Resource Development |
| Analytics | Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. | Informational | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. | Informational | Identity Analytics | XDR Agent | Discovery, Credential Access |
| Analytics | SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |