Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. tactic: TA0009 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Collection |
| Analytics BIOC | Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Reconnaissance |
| Analytics BIOC | Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Collection |