Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. tactic: TA0004 ✕ technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC The CA policy EditFlags was queried The CA policy EditFlags was queried. Medium Platform Analytics XDR Agent Privilege Escalation