Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

3 detectors match the current filters. tactic: TA0006 ✕ technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation