Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. tactic: TA0006 ✕ technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics | A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Persistence, Privilege Escalation, Credential Access |
| Analytics | Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Privilege Escalation |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics | Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Initial Access |
| Analytics | Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. | Informational | Identity Analytics | XDR Agent | Credential Access, Privilege Escalation |