Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
895 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Suspicious SMB connection from domain controller A domain controller has initiated an SMB connection to another host. The domain controllers usually communicate over SMB only with other domain controllers. An attacker can abuse such sessions for relay attacks. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |
| Analytics BIOC | Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. | Low | Platform Analytics | XDR Agent | Execution, Persistence, Privilege Escalation |
| Analytics BIOC | Suspicious time provider registered The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| BIOC | Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Suspicious usage of File Server Remote VSS Protocol (FSRVP) A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done. | High | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. | Low | Platform Analytics | XDR Agent | Defense Evasion, Persistence |
| BIOC | SyncAppvPublishingServer used to run PowerShell code SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | System information discovery via psinfo.exe Using psinfo.exe, the attacker can gather information about the network, and gain an in-depth understanding of which devices are relevant to attack. | Low | Platform Analytics | XDR Agent | Discovery |
| BIOC | System network configuration discovery System network configuration discovery using Linux command-line utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System owner/user discovery System owner/user discovery using bash utilities. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| Analytics BIOC | System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. | Low | Platform Analytics | Registry | Defense Evasion, Impact |
| Analytics BIOC | Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Security Support Provider DLLs Windows Security Support Provider (SSP) DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored on Windows, such as any logged-on user's Domain password etc. CurrentControlSet is replaced with * because it can be replaced with ControlSet001 or ControlSet002. | Informational | Platform Analytics | Registry | Persistence |
| BIOC | Task scheduled by commonly abused host process Attackers will often attempt to abuse shell/host processes to create a persistent payload in the form of a scheduled task. Check for malicious use. | Informational | Platform Analytics | Process execution | Persistence |
| Analytics BIOC | The CA policy EditFlags was queried The CA policy EditFlags was queried. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | The Linux system firewall was disabled The system firewall was disabled. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | The scripting engine executed code from an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. An attacker may try to evade detection by executing malware from the ADS value of a file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | UAC bypass using the changepk.exe Registry key Attackers may use the changepk.exe built-in Windows tool to bypass Windows UAC by modifying Registry keys. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | UDP protocol scanner execution The UDP Protocol Scanner performs UDP service discovery. Attackers may use it to enumerate UDP services in their target's environment. | Low | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon access to cloud platforms' sensitive files by a scripting engine A scripting engine has accessed sensitive cloud platforms' files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. | Low | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. | Medium | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. | Informational | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. | Low | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. | Low | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. | Low | Platform Analytics | XDR Agent | Execution, Exfiltration |
| Analytics BIOC | Uncommon ARP cache listing via arp.exe The arp.exe command is used to display and modify entries in the Address Resolution Protocol (ARP) cache. Adversaries may attempt to use the command to discover remote systems they could compromise. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Uncommon AT task-job creation by user An unpopular AT task-job was created by a user. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon browser extension loaded An uncommon browser extension was loaded by a Chromium-based browser. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon communication to an instant messaging server A rare communication between a process to a known instant messaging server. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon creation or access operation of sensitive shadow copy An uncommon creation or access of a sensitive Shadow Copy volume path. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion, Privilege Escalation |
| Analytics BIOC | Uncommon DotNet module load relationship A signed process that usually doesn't use DotNet loaded a common DotNet module. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon file access over WebDAV Uncommon file access over WebDAV. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Uncommon IP Configuration Listing via ipconfig.exe The 'ipconfig' command is used to display TCP/IP network configuration information and refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Adversaries may use the command to discover network configuration details. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Uncommon jsp file write by a Java process An uncommon jsp file was written by a Java process. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon kernel module load Loading of a kernel module using the modprobe command. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon Launch Agent persistency was registered or modified An uncommon Launch Agent persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon Launch Daemon persistency was registered or modified An uncommon Launch Daemon persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon Linux process communication to a rare external host An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution, Lateral Movement |
| Analytics BIOC | Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon local scheduled task creation via schtasks.exe The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to gain persistence on this host using scheduled tasks. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon login item persistency was registered or modified An uncommon login item persistence mechanism was registered/modified on the system. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon macOS process communication to a rare external host An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon Managed Object Format (MOF) compiler usage The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon network tunnel creation An uncommon network tunnel was established. | Informational | Platform Analytics | Palo Alto Networks Url Logs | Command and Control |
| Analytics BIOC | Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Uncommon PowerShell commands used to create or alter scheduled task parameters Attackers may create or alter scheduled task parameters to gain higher privileges or persistence on the system. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. | Informational | Platform Analytics | XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon routing table listing via route.exe The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Uncommon Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Uncommon sensitive filesystem registry hive access A sensitive registry hive was accessed from the filesystem by an uncommon actor, which is used for credentials dumping. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon sensitive registry hive dump A sensitive registry hive was extracted, which is used for accessing credentials. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Collection |
| Analytics BIOC | Uncommon signed process execution by scheduled task An uncommon process was executed by a scheduled task. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon SQL like command line Uncommon SQL query in command line of an executed process. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Uncommon SSH session was established An uncommon SSH session was established. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon VNC server communication Uncommon VNC server network traffic was observed. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics | Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics BIOC | Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. | High | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Unpopular rsync process execution An unpopular rsync process was executed on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |