Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
895 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | SecureBoot was disabled SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| BIOC | Security services stopped Attackers may stop security critical services to avoid possible detection of their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. | Informational | Platform Analytics | Registry | Privilege Escalation |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| BIOC | SELinux was set to permissive mode SELinux was set to permissive mode using the "setenforce 0" command. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| BIOC | Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. | Medium | Platform Analytics | Windows event log | Discovery |
| BIOC | Shell binary copied to another location Attackers may try to evade detection by copying the shell binary to an innocent-looking name. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | File | Credential Access, Collection |
| BIOC | Shell history access Attackers may search historical commands for credentials and information gathering. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | Process execution | Credential Access, Collection |
| BIOC | Shim database file access An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence. | Informational | Platform Analytics | File | Persistence, Privilege Escalation |
| BIOC | Shim database registration via Registry Application shim databases may be leveraged for privilege escalation and persistence, and can be installed by modifying the Registry. | Informational | Platform Analytics | Registry | Persistence |
| BIOC | Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. | Informational | Platform Analytics | Process execution | Impact |
| Analytics BIOC | Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by Cymulate Simulation activity performed by Cymulate agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | SmartScreen disabled via Registry These Registry keys control the SmartScreen. Malware may turn it off to evade SmartScreen functionality. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | SMB enumeration via command-line tool Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | SMB Traffic from Non-Standard Process SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. | Low | Platform Analytics | XDR Agent | Discovery |
| BIOC | Socat/Netcat connects to TOR domain Unlikely behavior in standard systems. | Medium | Platform Analytics | Network | Command and Control |
| Analytics BIOC | Space after filename A file was created or renamed to have a space at the end of its name. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. | Informational | Platform Analytics | File | Defense Evasion |
| Analytics | Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Impact |
| BIOC | SSH key pair discovery Attackers may look for SSH key pairs using the find command. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Subdomain Fuzzing The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics | Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| Analytics BIOC | SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. | Low | Platform Analytics | XDR Agent | Discovery |
| BIOC | SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. | High | Platform Analytics | Module | Initial Access, Command and Control |
| Analytics BIOC | Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Suspicious .NET process spawns csc.exe A suspicious process in the Microsoft .NET directory spawned the C# compiler. This may occur if an attacker masquerades a process like MSBuild (e.g. PowerLessShell). | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. | Informational | Platform Analytics | File | Discovery |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious active setup registered The endpoint registered a new active setup, which may be used to gain persistence on the host by loading libraries into the time management service. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious AMSI decode attempt A script has executed commands that can be used to decode commands or files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Suspicious AMSI DLL load location An attacker may attempt to load a malicious copy of amsi.dll to bypass Microsoft's Antimalware Scan Interface (AMSI). | Low | Platform Analytics | Module | Defense Evasion |
| Analytics BIOC | Suspicious authentication package registered The endpoint registered a suspicious authentication package, which may be used to gain persistence on the host by loading libraries into the time management service. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious Certutil AD CS contact A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface. | Low | Platform Analytics | XDR Agent | Discovery, Credential Access |
| Analytics BIOC | Suspicious certutil command line An attacker may use certutil to download malware. | Medium | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. | Low | Platform Analytics | XDR Agent | Execution, Persistence, Privilege Escalation |
| Analytics | Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious curl user agent Suspicious user agent provided to curl command. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. | Low | Platform Analytics | XDR Agent | Impact, Defense Evasion |
| BIOC | Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. | High | Platform Analytics | File | Credential Access |
| Analytics BIOC | Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Suspicious DLL load using Control.exe This execution mechanism is known to be used by malware to load malicious DLLs. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious DotNet log file created Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious Encrypting File System Remote call (EFSRPC) to domain controller An Encrypting File System Remote call (EFSRPC) was made to a domain controller. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| BIOC | Suspicious executable created in a .NET directory Cmd.exe created an executable file in the Microsoft .NET directory. This behavior is exhibited in the PowerLessShell tool to disguise MSBuild.exe. | High | Platform Analytics | File | Defense Evasion |
| Analytics BIOC | Suspicious failed HTTP request - potential Spring4Shell exploit A potentially malicious failed HTTP request was received, possibly as part of a Spring4Shell exploitation attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access |
| BIOC | Suspicious file created in AppData directory A suspicious executable file was created in the AppData directory. | Informational | Platform Analytics | File | Execution |
| Analytics BIOC | Suspicious HTTP parameters detected The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access, Persistence |
| Analytics BIOC | Suspicious ICMP packet An ICMP router advertisement was sent by a host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics | Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. | Low | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious LDAP queries followed by shared folder access The user executed suspicious LDAP queries shortly before accessing a shared folder. This behavior may be indicative of Rubeus activity involving Kerberos ticket forgery, such as Golden Ticket or Silver Ticket attacks. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious LDAP search query executed A suspicious and unpopular LDAP search query was executed. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Suspicious lock screen image file written to disk Desktopimgdownldr.exe is a built-in Windows tool used to set a lock screen or desktop background image as part of Personalization CSP. Adversaries may use it maliciously to download malware. | Low | Platform Analytics | File | Command and Control |
| Analytics BIOC | Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Suspicious PowerShell Enumeration of Running Processes Attackers often enumerate running processes to find and disable security tools. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Suspicious PowerSploit's recon module (PowerView) net function was executed An attacker may use PowerSploit to reconnaissance the network. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Suspicious print processor registered The endpoint registered a new print processor, which may be used to gain persistence on the host by loading libraries into the time management service. | Medium | Platform Analytics | XDR Agent | Persistence |
| BIOC | Suspicious printer driver installation A suspicious process installed a generic printer driver. This may be a sign of CVE-2020-1048, in which an attacker attempts to overwrite a file on the OS. | Low | Platform Analytics | Registry | Privilege Escalation, Persistence |
| BIOC | Suspicious printer port creation via Registry An attacker may create a print job that prints to a file, overwriting any file on the OS (CVE-2020-1048). | Medium | Platform Analytics | Registry | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. | Informational | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious process accessed certificate files A suspicious process accessed certificate files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. | Informational | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Suspicious process execution from tmp folder An unpopular process was executed from the tmp folder. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Suspicious process loads AMSI DLL Amsi.dll is expected to be loaded from a few known processes (e.g. PowerShell). An image load from an unrelated LOLBIN may indicate PowerShell execution. | Informational | Platform Analytics | Module | Execution |
| Analytics BIOC | Suspicious process modified RC script file A suspicious process modified an RC script file. These files allow system administrators to map and start custom services at startup for different run levels. This may be done to establish persistence. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Suspicious Process Spawned by Adobe Reader Unusual process spawned by Adobe Reader with an uncommon command line. | Low | Platform Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious Process Spawned by wininit.exe An unusual process was spawned by wininit.exe, possibly indicating malicious local or remote code execution. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Suspicious process spawns MSBuild.exe The Microsoft Build Engine was started by an abnormal process. MSBuild is normally used for development purposes, so this unusual behavior may be malicious. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Suspicious proxy environment variable setting Suspicious proxy environment variable change or definition with a rare command line. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics | Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Suspicious RunOnce Parent Process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user login events. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious runonce.exe parent process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user logon events. | Low | Platform Analytics | XDR Agent | Persistence |
| BIOC | Suspicious SDB file written to disk Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files may be indicative of this technique. | Informational | Platform Analytics | File | Persistence |
| BIOC | Suspicious SDB file written to disk by an unsigned process Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files by an unsigned process may be indicative of this technique. | Informational | Platform Analytics | File | Persistence |
| Analytics BIOC | Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Suspicious setspn.exe execution A Service Principal Name (SPN) is a unique identifier for a service, mapped to a specific account. Setspn.exe can be used to retrieve SPN information, which may indicate an attacker's attempt to "Kerberoast". | Low | Platform Analytics | XDR Agent | Credential Access |