Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

474 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. Informational Platform Analytics Process execution Collection
BIOC Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. Informational Platform Analytics Process execution Discovery, Execution
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
BIOC Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. Informational Platform Analytics Process execution Defense Evasion, Discovery
BIOC Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. Informational Platform Analytics File Initial Access
BIOC Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. Informational Platform Analytics File Lateral Movement
Analytics BIOC Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of an uncommon process at an early startup stage Uncommon execution of an executable found in an early startup stage. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process with a local/domain user SID at an early startup stage Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused. Informational Platform Analytics XDR Agent Persistence
BIOC Execution of commonly abused AutoIT script AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Execution of regsvcs/regasm with uncommon paths The regasm.exe/regsvcs.exe commands are used to register .NET COM assemblies, which are typically located in specific paths. Uncommon paths may indicate malicious code is being registered. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Execution of WSL Distro Detecting a new instance execution of Windows Subsystem for Linux distro. Informational Platform Analytics File Defense Evasion
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
BIOC File renamed to have a script extension Adversaries may create 'benign-looking' files, which are later used as malicious scripts by changing their extension. Informational Platform Analytics File Defense Evasion
BIOC File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. Informational Platform Analytics XDR Agent Command and Control
BIOC Fltmc.exe used to unload filter driver Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring. Informational Platform Analytics Process execution Defense Evasion
BIOC Fontdrvhost.exe makes network connections A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Network Execution
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
Analytics BIOC Globally uncommon high entropy module was loaded A module with high entropy and a globally uncommon hash was loaded. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon high entropy process was executed A process with high entropy and a globally uncommon hash was executed. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon image load from a signed process A signed process loaded a DLL that, on a global level, it usually doesn't load. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. Informational Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC Globally uncommon IP address by a common process (sha256) A process with a common sha256 connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Globally uncommon root-domain port combination by a common process (sha256) A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
BIOC Grepping for passwords Attackers may look for cleartext passwords in files using the grep command. Informational Platform Analytics Process execution Credential Access
BIOC Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. Informational Platform Analytics Process execution Discovery
BIOC GUI Input Capture Prompt user to supply a password in response to a System Preference dialog pop up message. Informational Platform Analytics Process execution Credential Access
Analytics BIOC Hidden Attribute was added to a file using attrib.exe Hidden attribute was added to a file using attrib.exe, adversaries may set files to be hidden to evade detection mechanisms. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Hidden directory creation Attackers may create hidden directories to hide malware or staged files. Informational Platform Analytics Process execution Defense Evasion
BIOC Hidden file and directory creation Creation of a hidden file inside a hidden directory. Informational Platform Analytics File Defense Evasion
Analytics BIOC Indicator blocking Auditing or logging configuration changes on Linux host. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Injection into ping.exe A process injected into an instance of ping.exe. Informational Platform Analytics Remote code Defense Evasion
Analytics BIOC Injection into rundll32.exe A process injected into an instance of rundll32.exe. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. Informational Platform Analytics Process execution Discovery
BIOC Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. Informational Platform Analytics Process execution Discovery
BIOC Internet Explorer security settings modification The Security Settings Check feature, which checks Internet Explorer security settings to determine risk, was disabled. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC Iptables configuration command was executed The iptables process was executed with a command to add or delete rules on the host. Informational Platform Analytics XDR Agent Defense Evasion
BIOC ISO mounted manually A user manually mounted an ISO file. Informational Platform Analytics File Defense Evasion
BIOC Kerberos brute-force attack using Kerbrute This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks. Informational Platform Analytics Process execution Credential Access
Analytics Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
BIOC Kernel modules loaded via command-line tool The insmod/depmod command loads a kernel module; attackers may use kernel modules as rootkits. Informational Platform Analytics Process execution Persistence
BIOC Kernel modules loaded via compiled loader and .ko file Instead of using insmod/depmod, an attacker can build a loader and load a kernel module; attackers may use kernel modules as rootkits. Informational Platform Analytics Process execution Persistence
BIOC Key Certificate Search And Exfiltrate Possible attempt to search for key certificates and exfiltrate them. Informational Platform Analytics Process execution Credential Access
BIOC Keychain Certificate Access Detected access to Keychain certificates. Informational Platform Analytics Process execution Credential Access
BIOC Keychain Import Item An item was imported from the Keychain. Informational Platform Analytics Process execution Credential Access
BIOC Keychain Unlock Detected Keychain unlocking. Informational Platform Analytics Process execution Credential Access
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. Informational Platform Analytics XDR Agent Discovery
BIOC Linux network share discovery A Linux network share discovery command was executed. Informational Platform Analytics Process execution Discovery
Analytics BIOC Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local group enumeration via RPC A user enumerated local groups via RPC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Local user enumeration via SAMR A user enumerated local users via SAMR. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Log deletion in known log file directories Deletion of log files in known log directories. Informational Platform Analytics File Defense Evasion
BIOC Log deletion using the truncate command Usage of the truncate utility using "-s 0" argument to clear log files. Informational Platform Analytics Process execution Defense Evasion
BIOC Log deletion via command-line tool An attacker may use the rm command to remove traces of their activities. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC LOLBAS executable injects into another process A signed binary, which can be abused to run code, injected code to another process. Informational Platform Analytics XDR Agent Defense Evasion
BIOC LOLBAS reading a Windows credential manager file Encrypted files under the path AppData\Roaming\Microsoft\Credentials are associated with saved passwords in the Windows system. Informational Platform Analytics File Credential Access
Analytics BIOC LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
BIOC MacOS firewall manipulation An attacker may modify a firewall via command line to bypass network controls. Informational Platform Analytics Process execution Defense Evasion
BIOC Malicious NetSetupSvc.dll loaded into svchost.exe A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe. Informational Platform Analytics Module Execution
BIOC Manipulation of 'BootExecute' Registry run key Smss.exe will launch anything present in the BootExecute Registry key under HKLM\SYSTEM\ControlSet002\Control\Session Manager. The BootExecute key should only contain "autocheck autochk*". If there are additional values in it, they are probably used for malware persistence. Informational Platform Analytics Registry Persistence
BIOC Manipulation of AppInit DLL loading list The AppInit DLLs Registry key contains a list of DLLs that will be loaded when user32.dll is loaded. As most Windows executables use the user32.dll, any DLL that is listed in the AppInit_DLLs Registry key will be loaded also. The user32.dll file is also used by processes that are automatically started by the system when you log on. Informational Platform Analytics Registry Persistence
BIOC Manipulation of Application Verifier custom providers The Application Verifier assists developers in quickly finding subtle programming errors that can be extremely difficult to identify with normal application testing. Using Application Verifier in Visual Studio makes it easier to create reliable applications by identifying errors caused by heap corruption, incorrect handle and critical section usage. Changing the providers could change handling. An attacker can use this ability to inject a custom verifier into any application. Once the custom verifier has been injected, the attacker now has full control over the application. Informational Platform Analytics Registry Persistence
BIOC Manipulation of autostart related system files May be used as a malware persistence technique, as these files have relevancy to the startup routine of Windows. Informational Platform Analytics File Persistence
BIOC Manipulation of Crypto Subject Interface Package (SIP) Provider Malicious modification of crypto subject interface package (SIP) provider Registry keys can be leveraged to trick the OS into incorrectly validating invalid signing certificates. May have legitimate uses, but check for malicious activity. Informational Platform Analytics Registry Defense Evasion
BIOC Manipulation of default file association configuration When a file is opened, the default program used to open the file, its handler, is checked. File association selections are stored in the Windows Registry and can be edited by users. Malware can modify or create a file association for a given file extension to call another program when a given extension is opened. Informational Platform Analytics Registry Persistence
BIOC Manipulation of MMC Registry configuration Creation or modification of these Microsoft Management Console related entries can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics Registry Privilege Escalation
BIOC Manipulation of permissions for the Application Event Log Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx. Informational Platform Analytics Registry Impact
BIOC Manipulation of RDP settings Possible modification of Terminal Services/RDP settings. Informational Platform Analytics Registry Lateral Movement
BIOC Manipulation of service imagepath configuration This key specifies the location of the executable file for the driver or service. Malicious executables might be installed in these paths. Informational Platform Analytics Registry Persistence
BIOC Manipulation of Volume Shadow Copy configuration Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy. Informational Platform Analytics Registry Impact
BIOC Manipulation of Windows Defender configuration Commands used to bypass, disable or harm Windows Defender. Informational Platform Analytics Process execution Defense Evasion
BIOC Manipulation of Windows Event Log auto-backup via Registry This key enables/disables the automatic backups of event logs when they are full. Informational Platform Analytics Registry Defense Evasion
BIOC Manipulation of Winlogon 'Notify' autostart Registry key Since Winlogon handles the Secure Attention Sequence (SAS) (Ctrl+Alt+Del), notify subkeys found at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify are used to notify event handles when SAS happens and load a DLL. This DLL can be edited to launch whenever such a SAS event occurs. Informational Platform Analytics Registry Persistence
BIOC Microsoft HTML Application Host spawns from CMD or PowerShell Microsoft HTML Application Host is a program whose source code consists of HTML, Dynamic HTML and a few scripting languages compatible with Internet Explorer such as VBScript or JScript. It does not typically spawn from PowerShell or CMD. Informational Platform Analytics Process execution Defense Evasion
BIOC Microsoft HTML Application Host spawns from Explorer.exe Mshta allows execution of .hta files, an attacker can use mshta to execute malicious hta files on the victim's host. Informational Platform Analytics Process execution Defense Evasion
BIOC Microsoft Office executes an unsigned process in a suspicious directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns an unsigned process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office spawns curl/wget on a macOS device Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device. Informational Platform Analytics Process execution Exfiltration
BIOC Modification of default Windows startup path via Registry An attacker may modify the startup path to the location of the malware. Informational Platform Analytics Registry Persistence
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
BIOC Modification of systemd service files An attacker may create or modify systemd service unit files to establish persistence between reboots. Informational Platform Analytics File Persistence
BIOC Modification of the Winlogon\Shell Registry key Malware may modify the Winlogon\Shell Registry value to load itself instead of explorer.exe, which is the default system shell. Informational Platform Analytics Registry Persistence
BIOC Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. Informational Platform Analytics Process execution Defense Evasion, Impact