Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

59 detectors match the current filters. tactic: TA0011 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. Informational Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics A compromised process accessed a rare external host A compromised process accessed a rare external host. Low Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics BIOC A process connected to a rare cloud resource A process connected to a rare cloud resource. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC A process connected to a rare external host A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process connected to rare external host A process connected to a rare external host. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal process connection to default Meterpreter port This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
Analytics Failed DNS The endpoint is performing DNS lookups that are failing at an excessively high rate when compared to its peer group. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics BIOC File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address by a common process (sha256) A process with a common sha256 connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon root-domain port combination by a common process (sha256) A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics HTTP with suspicious characteristics Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC MpCmdRun.exe was used to download files into the system Attackers might be using legitimate Windows Defender executables to download malicious code onto the system. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. High Platform Analytics XDR Agent Command and Control
Analytics Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics Rare access to known advertising domains The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Persistence
Analytics BIOC Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare binary connected to a rare cloud resource Rare binary connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare binary connected to a rare external host Rare binary connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare communication over email ports to external email server by unsigned process These methods are used by malware and attackers to leak data and remain undetected. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics BIOC Suspicious certutil command line An attacker may use certutil to download malware. Medium Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious curl user agent Suspicious user agent provided to curl command. Informational Platform Analytics XDR Agent Command and Control
Analytics Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Suspicious ICMP packet An ICMP router advertisement was sent by a host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration
Analytics BIOC Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. Informational Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious proxy environment variable setting Suspicious proxy environment variable change or definition with a rare command line. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon communication to an instant messaging server A rare communication between a process to a known instant messaging server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon Linux process communication to a rare external host An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon macOS process communication to a rare external host An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon SSH session was established An uncommon SSH session was established. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics Unusual SSH Activity Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics BIOC Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
Analytics BIOC Windows LOLBIN executable connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Medium Platform Analytics XDR Agent Command and Control