Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A remote service was created via RPC over SMB A remote service was created via RPC over SMB. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics | A user established an SMB connection to multiple hosts A user established an SMB connection to multiple hosts. This might indicate an enumeration attempt by a compromised account. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | An uncommon executable was remotely written over SMB to an uncommon destination An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics BIOC | Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | RDP connections enabled remotely via Registry An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |