Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. technique: T1564 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. | Informational | Identity Threat Detection (ITDR) | XDR Agent | Defense Evasion |
| Analytics BIOC | Hidden Attribute was added to a file using attrib.exe Hidden attribute was added to a file using attrib.exe, adversaries may set files to be hidden to evade detection mechanisms. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Credential Access |
| Analytics BIOC | Suspicious process execution from tmp folder An unpopular process was executed from the tmp folder. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unpopular rsync process execution An unpopular rsync process was executed on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |