Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
88 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. | Informational | Identity Threat Detection (ITDR) | XDR Agent | Defense Evasion |
| Analytics BIOC | A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A process was executed with a command line obfuscated by Unicode character substitution A process was executed with a command line obfuscated by Unicode character substitution. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics | An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. | Medium | Platform Analytics | XDR Agent | Persistence, Defense Evasion |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Execution of dllhost.exe with an empty command line The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Globally uncommon high entropy module was loaded A module with high entropy and a globally uncommon hash was loaded. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Globally uncommon high entropy process was executed A process with high entropy and a globally uncommon hash was executed. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Globally uncommon image load from a signed process A signed process loaded a DLL that, on a global level, it usually doesn't load. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Persistence |
| Analytics BIOC | Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Hidden Attribute was added to a file using attrib.exe Hidden attribute was added to a file using attrib.exe, adversaries may set files to be hidden to evade detection mechanisms. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Indicator blocking Auditing or logging configuration changes on Linux host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Indirect command execution using the Program Compatibility Assistant Pcalua.exe (Program Compatibility Assistant) is used for running old programs that have compatibility issues. Attackers can use pcalua.exe to indirectly execute their malicious programs. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Injection into rundll32.exe A process injected into an instance of rundll32.exe. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Iptables configuration command was executed The iptables process was executed with a command to add or delete rules on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | LOLBAS executable injects into another process A signed binary, which can be abused to run code, injected code to another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Masquerading as the Linux crond process Copies a file and renames it as crond. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Microsoft Office injects code into a process An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways. | Low | Platform Analytics | XDR Agent | Initial Access, Defense Evasion |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics BIOC | Mshta.exe launched with suspicious arguments Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Mshta.exe spawns from a browser process Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | MSI accessed a web page running a server-side script The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Msiexec execution of an executable from an uncommon remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Office process spawned with suspicious command-line arguments An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Ping to localhost from an uncommon, unsigned parent process Ping is often used by malware and attackers to delay the execution of suspicious commands in sandbox environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible binary padding using dd A suspicious dd command ran and added data to a binary. This may indicate binary padding to change the hash of a file. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible data obfuscation A command that can be used for file obfuscation was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Possible malicious .NET compilation started by a commonly abused process Attackers may use csc.exe to compile payloads on a compromised machine. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Credential Access |
| Analytics BIOC | Rare security product signed executable executed in the network Attackers may attempt to install a security product with a known vulnerability to bypass security features. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Registration of Uncommon .NET Services and/or Assemblies Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| Analytics BIOC | Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious certutil command line An attacker may use certutil to download malware. | Medium | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. | Low | Platform Analytics | XDR Agent | Impact, Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. | Informational | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious process execution from tmp folder An unpopular process was executed from the tmp folder. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious Process Spawned by wininit.exe An unusual process was spawned by wininit.exe, possibly indicating malicious local or remote code execution. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. | Low | Platform Analytics | XDR Agent | Defense Evasion, Persistence |
| Analytics BIOC | Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | The Linux system firewall was disabled The system firewall was disabled. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. | Low | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion, Privilege Escalation |
| Analytics BIOC | Uncommon DotNet module load relationship A signed process that usually doesn't use DotNet loaded a common DotNet module. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon kernel module load Loading of a kernel module using the modprobe command. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. | High | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unpopular rsync process execution An unpopular rsync process was executed on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Discovery |
| Analytics BIOC | Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Defense Evasion, Persistence |
| Analytics BIOC | Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |