Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

75 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Adding execution privileges A script was granted execution privileges using chmod before being run. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command execution via wmiexec Attackers may use WMI to execute commands on the target host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. Low Platform Analytics XDR Agent Execution
Analytics BIOC Download a script using the python requests module Download a shell script from a remote location using the Python requests module. Low Platform Analytics XDR Agent Execution
Analytics BIOC Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Interactive at.exe privilege escalation method Detects an interactive AT scheduled task, which may be used as a form of privilege escalation. Low Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. Medium Platform Analytics XDR Agent Execution, Discovery
Analytics BIOC Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. Medium Platform Analytics XDR Agent Execution
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Rare LOLBIN Process Execution by User A user executed a living-off-the-land binary (LOLBIN) process that is unusual for this user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics BIOC Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. Low Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. High Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. Informational Cortex Cloud XDR Agent Execution
Analytics BIOC Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). Medium Platform Analytics XDR Agent Execution, Defense Evasion, Privilege Escalation
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. Medium Cortex Cloud XDR Agent Execution
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution