Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
3 detectors match the current filters. tactic: TA0003 ✕ technique: T1574 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Defense Evasion |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |