Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

26 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A machine certificate was issued with a mismatch A machine certificate was issued with a mismatch between the requester and the subject. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Executable created to disk by lsass.exe Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Machine account was added to a domain admins group A machine account was added to a domain admins group. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible Persistence via group policy Registry keys Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious dNSHostName attribute change to DC name The dNSHostName attribute of a machine account was changed to a Domain Controller server name. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious Encrypting File System Remote call (EFSRPC) to domain controller An Encrypting File System Remote call (EFSRPC) was made to a domain controller. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Suspicious hidden user created A user account was created with a name that mimics a machine account. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Defense Evasion
Analytics BIOC Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) net function was executed An attacker may use PowerSploit to reconnaissance the network. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC TGT request with a spoofed sAMAccountName - Event log A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Uncommon jsp file write by a Java process An uncommon jsp file was written by a Java process. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Collection
Analytics BIOC Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence