Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

29 detectors match the current filters. technique: T1021 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics BIOC Rare file transfer over SMB protocol The endpoint performed an abnormal file transfer over SMB to a remote host. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC RDP Connection to localhost An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote WMI process execution A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution