Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
56 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser extension was installed or loaded in an uncommon way A browser extension was installed or loaded in an uncommon way. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. | Informational | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | A WMI subscriber was created A WMI subscriber was created. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. | Informational | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | An uncommon file added to startup-related Registry keys An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An uncommon file was created in the startup folder An uncommon file was created in the startup folder. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Browser Extension Installed Uncommon browser extension installed. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics BIOC | Local group enumeration via RPC A user enumerated local groups via RPC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Local user enumeration via SAMR A user enumerated local users via SAMR. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics | Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare scheduled task created A new rare scheduled task was created with a rare path and a rare command line. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Space after filename A file was created or renamed to have a space at the end of its name. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious active setup registered The endpoint registered a new active setup, which may be used to gain persistence on the host by loading libraries into the time management service. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious AMSI decode attempt A script has executed commands that can be used to decode commands or files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics | Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| Analytics BIOC | Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Uncommon browser extension loaded An uncommon browser extension was loaded by a Chromium-based browser. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual ADConnect database file access An unusual process accessed the ADConnect database files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics | User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| Analytics BIOC | VM Detection attempt A script has executed commands that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics | Web server CGO executed a process following a potential Webshell dropped A process was executed by a web server CGO following a potential drop of a webshell file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |