Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

3 detectors match the current filters. tactic: TA0002 ✕ technique: T1059 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. High Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Execution