Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
80 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. | Informational | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics | A compromised process accessed a rare external host A compromised process accessed a rare external host. | Low | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics | A user accessed multiple time-consuming websites A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics | A user authenticated with weak NTLM to multiple hosts A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics | A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Persistence, Privilege Escalation, Credential Access |
| Analytics | Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics | Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics | Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics | Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics | Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics | Abnormal SMB scanning activity to multiple hosts An endpoint performed a new, unfamiliar SMB scanning activity to multiple hosts on the network. | Informational | Platform Analytics | XDR Agent | Reconnaissance |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics | An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. | Medium | Platform Analytics | XDR Agent | Persistence, Defense Evasion |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics | DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics | External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| Analytics | Failed DNS The endpoint is performing DNS lookups that are failing at an excessively high rate when compared to its peer group. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics | HTTP with suspicious characteristics Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Increase in Job-Related Site Visits A user has visited multiple job-related sites in the past day. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics | Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. | Low | Identity Analytics | XDR Agent | Discovery, Credential Access |
| Analytics | Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. | Medium | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics | Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Large Upload (FTP) The endpoint transferred an excessively large amounts of data to a single destination over FTP. Cortex XDR Analytics assumes endpoint traffic towards a specific destination should be about the same over long periods of time. For that reason, Cortex XDR detected this abnormal behavior of a large data upload. An attacker may be exfiltrating data directly to the internet using this protocol. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration |
| Analytics | Large Upload (Generic) The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration |
| Analytics | Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics | Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics | Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access, Lateral Movement |
| Analytics | Massive upload to a rare storage or mail domain A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent | Exfiltration |
| Analytics | Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. | Informational | Identity Analytics | XDR Agent | Credential Access, Privilege Escalation |
| Analytics | Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. | Low | Identity Analytics | XDR Agent | Execution |
| Analytics | Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Execution |
| Analytics | Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Multiple users authenticated with weak NTLM to a host Multiple user accounts authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be a result of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics | Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics | New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics | NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. | Medium | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. | Informational | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access, Lateral Movement |
| Analytics | Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| Analytics | Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics | Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics | Possible TGT reuse from different hosts (pass the ticket) We observed two different hosts sending TGS using the same TGT. This may indicate a TGT was stolen and passed to another host. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics | Rare access to known advertising domains The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Persistence |
| Analytics | Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. | Informational | Identity Analytics | XDR Agent | Discovery, Credential Access |
| Analytics | Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Impact |
| Analytics | SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Subdomain Fuzzing The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics | Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics | Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. | Low | Platform Analytics | XDR Agent | Impact |
| Analytics | Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics | Unusual SSH Activity Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |