Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

215 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC WerFault ReflectDebugger key set in Registry The WerFault.exe signed Windows process may be tricked into running a malicious executable by setting the ReflectDebugger key in the Registry. Medium Platform Analytics Registry Defense Evasion
BIOC Windows 10 Developer Mode enabled Enabling developer mode allows for app sideloading and starts the Windows SSH services, which may be used to install Linux Bash on Windows. Informational Platform Analytics Registry Defense Evasion
BIOC Windows event logs cleared using wmic.exe Attackers may clear events from Windows event logs to remove traces of their malicious activity. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. Informational Platform Analytics Registry Defense Evasion
BIOC Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. Informational Platform Analytics Registry Defense Evasion
BIOC Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. Informational Platform Analytics Process execution Defense Evasion
BIOC Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. Informational Platform Analytics Windows event log Defense Evasion
BIOC Windows set to permit unsigned drivers (Test Mode) This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers. Medium Platform Analytics Process execution Defense Evasion
BIOC Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. Informational Platform Analytics Registry Defense Evasion
BIOC WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. Informational Platform Analytics Process execution Defense Evasion, Execution
Analytics BIOC Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. Low Platform Analytics XDR Agent Defense Evasion
BIOC WSL Feature Installation Detecting installation of Windows Subsystem for Linux feature. Informational Platform Analytics File Defense Evasion