Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics | Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Rare file transfer over SMB protocol The endpoint performed an abnormal file transfer over SMB to a remote host. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Uncommon VNC server communication Uncommon VNC server network traffic was observed. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |