Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
110 detectors match the current filters. tactic: TA0007 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Collection |
| Analytics | User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| BIOC | Virtual Directory configuration access via PowerShell PowerShell was used to dump Exchange Web Service (EWS) Virtual Directories, which may indicate malicious behavior, for example, SolarStorm campaign. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | VM Detection attempt A script has executed commands that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Discovery |
| BIOC | VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. | Informational | Platform Analytics | File | Discovery |