Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
45 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | A user account was modified to password never expires A user account was modified to password never expires. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user created a pfx file for the first time A user created a pfx file for the first time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| Analytics | A user established an SMB connection to multiple hosts A user established an SMB connection to multiple hosts. This might indicate an enumeration attempt by a compromised account. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A user was added to a Windows security group A user was added to a Windows security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics | Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Privilege Escalation |
| Analytics BIOC | Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Local group enumeration A user performed an enumeration on local groups to retrieve their details. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Local user account creation A user was observed creating a rare local user account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Local user account creation by a machine account A machine account was observed creating a rare local user account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Member added to a Windows local security group A member was added to a Windows local security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Defense Evasion |
| Analytics | Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Multiple user accounts were deleted A user deleted multiple user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Impact |
| Analytics BIOC | PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Privilege Escalation |
| Analytics BIOC | Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible GPO Enumeration A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics BIOC | Privileged certificate request via certificate template A privileged certificate was requested via certificate template. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Rare machine account creation A user was observed creating a machine account for the first time. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | SCCM log files enumeration Multiple local SCCM logs were accessed within a short period of time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics | Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious domain user account creation A user was observed creating a rare domain account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | User account delegation change A user account was modified with delegation to a service. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Defense Evasion |
| Analytics | User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |