Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
3 detectors match the current filters. tactic: TA0011 ✕ technique: T1105 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | MpCmdRun.exe was used to download files into the system Attackers might be using legitimate Windows Defender executables to download malicious code onto the system. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Suspicious certutil command line An attacker may use certutil to download malware. | Medium | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |