Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics | Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. | Low | Identity Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Low | Platform Analytics | XDR Agent | Execution |