Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

31 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A compiled HTML help file wrote a script file to the disk A compiled HTML help file wrote a script file to the disk. Compiled HTLM help files usually don't write script files to the disk. This behavior is often employed by malware that leverages malicious CHM files to deliver a 2nd stage payload. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A user modified the CA audit policy A user modified the CA audit policy. This may indicate that an attacker is attempting to cover their tracks before an AD CS attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Executable created to disk by lsass.exe Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Linux system firewall was modified The system firewall was modified. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics BIOC Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Defense Evasion
Analytics BIOC Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics BIOC Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics BIOC Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics Short-lived user account A user was created and deleted within a short period of time. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious AMSI decode attempt A script has executed commands that can be used to decode commands or files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious DotNet log file created Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious hidden user created A user account was created with a name that mimics a machine account. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Defense Evasion
Analytics BIOC Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Command and Control
Analytics BIOC Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Defense Evasion
Analytics BIOC User set insecure CA registry setting for global SANs A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion