Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. technique: T1548 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion