Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. tactic: TA0002 ✕ technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution, Lateral Movement |
| Analytics BIOC | WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |