Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Impact
Analytics BIOC A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. Informational Platform Analytics XDR Agent Impact
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics BIOC Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. Low Platform Analytics XDR Agent Impact, Defense Evasion
Analytics Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. Low Platform Analytics XDR Agent Impact
Analytics BIOC System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. High Platform Analytics XDR Agent Impact
Analytics BIOC Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. Low Platform Analytics XDR Agent Impact