Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. tactic: TA0003 ✕ technique: T1574 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
Analytics BIOC Phantom DLL Loading An attacker might leverage existing processes missing module loads to load malicious code into trusted processes. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. Low Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion