Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. technique: T1218 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of dllhost.exe with an empty command line The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Mshta.exe launched with suspicious arguments Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Mshta.exe spawns from a browser process Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. Low Platform Analytics XDR Agent Defense Evasion