Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. tactic: TA0004 ✕ technique: T1548 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC LOLBIN process executed with a high integrity level A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. Low Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. Low Platform Analytics Windows Event Collector, XDR Agent Privilege Escalation
Analytics BIOC Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. Low Platform Analytics XDR Agent Privilege Escalation, Defense Evasion
Analytics BIOC Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. Informational Platform Analytics XDR Agent Privilege Escalation