Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

131 detectors match the current filters. tactic: TA0003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Suspicious time provider registered The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. Low Platform Analytics XDR Agent Defense Evasion, Persistence
BIOC Tampering with Windows Security Support Provider DLLs Windows Security Support Provider (SSP) DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored on Windows, such as any logged-on user's Domain password etc. CurrentControlSet is replaced with * because it can be replaced with ControlSet001 or ControlSet002. Informational Platform Analytics Registry Persistence
BIOC Task scheduled by commonly abused host process Attackers will often attempt to abuse shell/host processes to create a persistent payload in the form of a scheduled task. Check for malicious use. Informational Platform Analytics Process execution Persistence
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AT task-job creation by user An unpopular AT task-job was created by a user. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon browser extension loaded An uncommon browser extension was loaded by a Chromium-based browser. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon jsp file write by a Java process An uncommon jsp file was written by a Java process. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon Launch Agent persistency was registered or modified An uncommon Launch Agent persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon Launch Daemon persistency was registered or modified An uncommon Launch Daemon persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon local scheduled task creation via schtasks.exe The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon login item persistency was registered or modified An uncommon login item persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon Managed Object Format (MOF) compiler usage The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon PowerShell commands used to create or alter scheduled task parameters Attackers may create or alter scheduled task parameters to gain higher privileges or persistence on the system. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon signed process execution by scheduled task An uncommon process was executed by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
BIOC User added to local administrator group using a PowerShell command Adding a new user to the local admin group may or may not be malicious, but it is an outstanding action worth considering, as it shouldn't happen too often. A malware may add a new malicious user to the administrators group as a way of maintaining high privileges after the system was compromised. Medium Platform Analytics Process execution Persistence
BIOC User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. Informational Platform Analytics File Persistence
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence
Analytics Web server CGO executed a process following a potential Webshell dropped A process was executed by a web server CGO following a potential drop of a webshell file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. Informational Platform Analytics XDR Agent Initial Access, Persistence
BIOC Write to .bash_profile Commands in ~/.bash_profile are executed on every user shell login with a username and password. Informational Platform Analytics File Persistence