Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

3 detectors match the current filters. tactic: TA0043 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Abnormal RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics BIOC Suspicious access of the System Management Container A user accessed the System Management container, which may be an indication of a reconnaissance for site servers. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics BIOC Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection, Reconnaissance