Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Defense Evasion
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious AMSI decode attempt A script has executed commands that can be used to decode commands or files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Defense Evasion
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion