Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

895 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC 64-bit PowerShell spawning a 32-bit PowerShell Malware typically spawns 32-bit processes to work on as many hosts as possible. This case is therefore suspicious when it happens on a 64-bit host. Low Platform Analytics Process execution Execution
BIOC 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
Analytics BIOC A browser extension was installed or loaded in an uncommon way A browser extension was installed or loaded in an uncommon way. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A compiled HTML help file wrote a script file to the disk A compiled HTML help file wrote a script file to the disk. Compiled HTLM help files usually don't write script files to the disk. This behavior is often employed by malware that leverages malicious CHM files to deliver a 2nd stage payload. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. Informational Platform Analytics XDR Agent Exfiltration
Analytics A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. Informational Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics A compromised process accessed a rare external host A compromised process accessed a rare external host. Low Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics BIOC A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A non-browser process accessed a website UI An uncommon network communication between a non-browser process and a website UI. Informational Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Impact
Analytics BIOC A process connected to a rare cloud resource A process connected to a rare cloud resource. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC A process connected to a rare external host A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process connected to rare external host A process connected to a rare external host. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC A process was executed with a command line obfuscated by Unicode character substitution A process was executed with a command line obfuscated by Unicode character substitution. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC A rare file path was added to the AppInit_DLLs registry value A rare file path was added to AppInit_DLLs registry value. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC A remote service was created via RPC over SMB A remote service was created via RPC over SMB. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
BIOC A scripting engine was called to run in command line Scripting engines that are called to run in command line are used by attackers to run a script payload without a UI. Informational Platform Analytics Process execution Execution
Analytics BIOC A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. Informational Platform Analytics XDR Agent Impact
Analytics BIOC A suspicious direct syscall was executed A suspicious direct syscall was executed. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Analytics BIOC A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics BIOC A WMI subscriber was created A WMI subscriber was created. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
Analytics Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics BIOC Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal process connection to default Meterpreter port This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. Informational Platform Analytics XDR Agent Command and Control
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics Abnormal RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal SMB scanning activity to multiple hosts An endpoint performed a new, unfamiliar SMB scanning activity to multiple hosts on the network. Informational Platform Analytics XDR Agent Reconnaissance
Analytics BIOC Access to kubelet credentials file A process accessed a kubelet credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
BIOC Accessing bash history file Clearing bash history file is a known procedure of attackers to delete traces. Low Platform Analytics Process execution Defense Evasion
BIOC Accessing bash history file using bash commands Clearing bash history files is a known attacker procedure for covering their tracks. Low Platform Analytics Process execution Defense Evasion
BIOC Account creation via command-line tool The useradd/adduser command could be used to create user accounts or to add users to existing groups. Informational Platform Analytics Process execution Persistence
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
BIOC Active Setup Registry Autostart Suspicious modification of the active setup registry for persistence and privilege escalation. Low Platform Analytics Registry Persistence
Analytics BIOC Adding execution privileges A script was granted execution privileges using chmod before being run. Informational Platform Analytics XDR Agent Execution
BIOC ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). Informational Platform Analytics Process execution Discovery
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Administrator obtains access rights to a file using icacls.exe Grant an administrator file access privileges. Informational Platform Analytics Process execution Defense Evasion
BIOC Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. Informational Platform Analytics File Initial Access
BIOC Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. Informational Platform Analytics Process execution Initial Access
Analytics AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Correlation Rule Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account Medium Platform Analytics alibaba_action_trail_raw
BIOC AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. Medium Platform Analytics Process execution Defense Evasion
BIOC An executable compiled with a py2exe-like program was executed A py2exe-like program DLL file dropped to disk. Informational Platform Analytics File Execution
Analytics An executable was written and executed by a web server Web server process had written an executable file that was executed shortly after. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon executable was remotely written over SMB to an uncommon destination An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC An uncommon file added to startup-related Registry keys An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon file was created in the startup folder An uncommon file was created in the startup folder. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. Medium Platform Analytics XDR Agent Persistence, Defense Evasion
Analytics BIOC Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. Informational Platform Analytics Palo Alto Networks Firewall threat Logs, XDR Agent Reconnaissance
Analytics BIOC AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
BIOC Base64 decoding using the base64 utility Base64 decoding using the base64 utility with the -d argument provided. Informational Platform Analytics Process execution Defense Evasion
BIOC Base64 encoding used Attackers may use the base64 built-in binary to encode data into base64. Informational Platform Analytics Process execution Command and Control
Analytics BIOC Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. Medium Platform Analytics XDR Agent Persistence
BIOC Bitsadmin.exe used to download data Some attacks were known for abusing BITSAdmin in the past to hide how data was downloaded using legitimate Windows tools. Informational Platform Analytics Process execution Persistence
BIOC Bitsadmin.exe used to upload data Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools. High Platform Analytics Process execution Exfiltration, Defense Evasion
BIOC BitTorrent P2P file sharing The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information. Informational Platform Analytics Dml connection Exfiltration
Analytics BIOC Broker Collection Error A collection error was detected on a broker VM. Informational Platform Analytics Health Monitoring Data Impact
Analytics BIOC Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. High Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Browser downloads an .hta or .application file .hta and .application files are Windows applications that may serve as an attack vector by executing code maliciously using trusted Windows applications. Informational Platform Analytics File Defense Evasion
Analytics BIOC Browser Extension Installed Uncommon browser extension installed. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
BIOC Built-in SoundRecorder tool capturing audio SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user. Informational Platform Analytics Process execution Collection