Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
17 detectors match the current filters. tactic: TA0003 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| Analytics | A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user was added to a Windows security group A user was added to a Windows security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Azure device code authentication flow used An Azure AD login was performed with device code flow. | Informational | Identity Analytics | Azure Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Linux local user account creation A user executed a process associated with user account creation. | Informational | Identity Analytics | XDR Agent | Persistence |
| Analytics BIOC | Local user account creation A user was observed creating a rare local user account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Local user account creation by a machine account A machine account was observed creating a rare local user account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Member added to a Windows local security group A member was added to a Windows local security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Defense Evasion |
| Analytics | Multiple user accounts were deleted A user deleted multiple user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Impact |
| Analytics BIOC | Rare machine account creation A user was observed creating a machine account for the first time. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious domain user account creation A user was observed creating a rare domain account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | User account delegation change A user account was modified with delegation to a service. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |