Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

257 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. Low Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC System information discovery via psinfo.exe Using psinfo.exe, the attacker can gather information about the network, and gain an in-depth understanding of which devices are relevant to attack. Low Platform Analytics XDR Agent Discovery
BIOC Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. Low Platform Analytics Registry Defense Evasion, Impact
Analytics BIOC The Linux system firewall was disabled The system firewall was disabled. Low Platform Analytics XDR Agent Defense Evasion
BIOC UDP protocol scanner execution The UDP Protocol Scanner performs UDP service discovery. Attackers may use it to enumerate UDP services in their target's environment. Low Platform Analytics Process execution Discovery
Analytics BIOC Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. Low Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon ARP cache listing via arp.exe The arp.exe command is used to display and modify entries in the Address Resolution Protocol (ARP) cache. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon AT task-job creation by user An unpopular AT task-job was created by a user. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon creation or access operation of sensitive shadow copy An uncommon creation or access of a sensitive Shadow Copy volume path. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon file access over WebDAV Uncommon file access over WebDAV. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics BIOC Uncommon IP Configuration Listing via ipconfig.exe The 'ipconfig' command is used to display TCP/IP network configuration information and refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Adversaries may use the command to discover network configuration details. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Uncommon PowerShell commands used to create or alter scheduled task parameters Attackers may create or alter scheduled task parameters to gain higher privileges or persistence on the system. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon routing table listing via route.exe The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Uncommon sensitive registry hive dump A sensitive registry hive was extracted, which is used for accessing credentials. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon SSH session was established An uncommon SSH session was established. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual compressed file password protection An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them. Low Platform Analytics XDR Agent Collection
Analytics BIOC Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Command and Control
Analytics BIOC Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection, Reconnaissance
Analytics BIOC Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Collection
Analytics BIOC Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Weakly-Encrypted Kerberos Ticket Requested A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes and is typically a sign of a Kerberoasting attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. Low Platform Analytics XDR Agent Impact
BIOC Windows File Protection being disabled via Registry Windows File Protection (WFP) prevents programs from replacing critical Windows system files. Programs must not overwrite these files because they are used by the operating system and by other programs. Protecting these files prevents problems with programs and the operating system. Low Platform Analytics Registry Impact
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
BIOC WSReset.exe UAC bypass Attackers may use WSReset.exe to bypass User Account Control (UAC). Low Platform Analytics Process execution Privilege Escalation