Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. technique: T1218 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Suspicious certutil command line An attacker may use certutil to download malware. Medium Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion