Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
131 detectors match the current filters. tactic: TA0003 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Suspicious time provider registered The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. | Low | Platform Analytics | XDR Agent | Defense Evasion, Persistence |
| BIOC | Tampering with Windows Security Support Provider DLLs Windows Security Support Provider (SSP) DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored on Windows, such as any logged-on user's Domain password etc. CurrentControlSet is replaced with * because it can be replaced with ControlSet001 or ControlSet002. | Informational | Platform Analytics | Registry | Persistence |
| BIOC | Task scheduled by commonly abused host process Attackers will often attempt to abuse shell/host processes to create a persistent payload in the form of a scheduled task. Check for malicious use. | Informational | Platform Analytics | Process execution | Persistence |
| Analytics BIOC | Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Uncommon AT task-job creation by user An unpopular AT task-job was created by a user. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon browser extension loaded An uncommon browser extension was loaded by a Chromium-based browser. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon jsp file write by a Java process An uncommon jsp file was written by a Java process. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon Launch Agent persistency was registered or modified An uncommon Launch Agent persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon Launch Daemon persistency was registered or modified An uncommon Launch Daemon persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon local scheduled task creation via schtasks.exe The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon login item persistency was registered or modified An uncommon login item persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon Managed Object Format (MOF) compiler usage The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon PowerShell commands used to create or alter scheduled task parameters Attackers may create or alter scheduled task parameters to gain higher privileges or persistence on the system. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon signed process execution by scheduled task An uncommon process was executed by a scheduled task. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| BIOC | User added to local administrator group using a PowerShell command Adding a new user to the local admin group may or may not be malicious, but it is an outstanding action worth considering, as it shouldn't happen too often. A malware may add a new malicious user to the administrators group as a way of maintaining high privileges after the system was compromised. | Medium | Platform Analytics | Process execution | Persistence |
| BIOC | User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. | Informational | Platform Analytics | File | Persistence |
| Analytics BIOC | Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Defense Evasion, Persistence |
| Analytics | Web server CGO executed a process following a potential Webshell dropped A process was executed by a web server CGO following a potential drop of a webshell file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |
| BIOC | Write to .bash_profile Commands in ~/.bash_profile are executed on every user shell login with a username and password. | Informational | Platform Analytics | File | Persistence |