Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0004 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC Execution of command from within a Kubernetes pod using kubelet credentials A command was executed from within a Kubernetes pod using Kubelet credentials. This activity allows an attacker to impersonate the node and perform privileged operations against the cluster API. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Installation of a new System-V service Installation of a new System-V service. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC Interactive at.exe privilege escalation method Detects an interactive AT scheduled task, which may be used as a form of privilege escalation. Low Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC LOLBIN process executed with a high integrity level A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Mount command was executed from within a Kubernetes pod to list all the attached filesystems The mount command was executed inside a Kubernetes pod to list all the attached filesystems, which may serve as a precursor to container escape and host filesystem access. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. Low Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. Low Platform Analytics Windows Event Collector, XDR Agent Privilege Escalation
Analytics BIOC Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. Low Platform Analytics XDR Agent Privilege Escalation, Defense Evasion
Analytics BIOC Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation