Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
20 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A compiled HTML help file wrote a script file to the disk A compiled HTML help file wrote a script file to the disk. Compiled HTLM help files usually don't write script files to the disk. This behavior is often employed by malware that leverages malicious CHM files to deliver a 2nd stage payload. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Defense Evasion |
| Analytics BIOC | Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Executable created to disk by lsass.exe Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Linux system firewall was modified The system firewall was modified. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Persistence |
| Analytics BIOC | Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | Space after filename A file was created or renamed to have a space at the end of its name. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious AMSI decode attempt A script has executed commands that can be used to decode commands or files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious DotNet log file created Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| Analytics BIOC | Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | VM Detection attempt A script has executed commands that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |