Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

895 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Unsigned integer Sudo privilege escalation Fixed in CVE-2019-14287, this known command line is used to exploit a bug in sudo to gain root privileges. Medium Platform Analytics Process execution Privilege Escalation
BIOC Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. Informational Platform Analytics File Credential Access
BIOC Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. Informational Platform Analytics File Credential Access
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
BIOC Unsigned process creates an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. Malware may attempt to evade discovery by placing their payload in an ADS. Informational Platform Analytics File Defense Evasion
Analytics BIOC Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. Medium Platform Analytics XDR Agent Defense Evasion, Privilege Escalation
BIOC Unsigned process injects code into a process An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack. Informational Platform Analytics Remote code Defense Evasion
BIOC Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. Informational Platform Analytics Network Exfiltration
BIOC Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Informational Platform Analytics File Credential Access
BIOC Unsigned process running from a temporary directory Malware often runs from a temporary folder. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Untrusted process contacted LLM API An untrusted process contacted an LLM API. Informational Platform Analytics XDR Agent Resource Development
Analytics BIOC Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual ADConnect database file access An unusual process accessed the ADConnect database files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual compressed file password protection An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them. Low Platform Analytics XDR Agent Collection
Analytics BIOC Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. Informational Platform Analytics XDR Agent Initial Access, Lateral Movement
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics BIOC Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Command and Control
Analytics BIOC Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection, Reconnaissance
Analytics BIOC Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Collection
Analytics BIOC Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. Informational Platform Analytics Process execution Privilege Escalation
BIOC Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Process execution Execution
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics Unusual SSH Activity Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics BIOC Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics BIOC Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
BIOC Usage of tracing tool An attacker may be trying to use a known tracing tool to gather information from other processes. Informational Platform Analytics Process execution Defense Evasion
BIOC User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. Informational Platform Analytics Registry Defense Evasion
BIOC User added to local administrator group using a PowerShell command Adding a new user to the local admin group may or may not be malicious, but it is an outstanding action worth considering, as it shouldn't happen too often. A malware may add a new malicious user to the administrators group as a way of maintaining high privileges after the system was compromised. Medium Platform Analytics Process execution Persistence
Analytics User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. Informational Platform Analytics File Persistence
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
BIOC VBScript execution from the command line Attackers may run VBScript code from the command line using signed processes such as Mshta. Informational Platform Analytics Process execution Execution
BIOC Virtual Directory configuration access via PowerShell PowerShell was used to dump Exchange Web Service (EWS) Virtual Directories, which may indicate malicious behavior, for example, SolarStorm campaign. Medium Platform Analytics Process execution Discovery
BIOC VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. Informational Platform Analytics Process execution Discovery
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. Informational Platform Analytics XDR Agent Defense Evasion, Discovery
BIOC VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. Informational Platform Analytics Process execution Discovery
Analytics BIOC Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. High Platform Analytics XDR Agent Impact
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence
Analytics BIOC Weakly-Encrypted Kerberos Ticket Requested A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes and is typically a sign of a Kerberoasting attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
BIOC Web browser cookie and credential access Detect attempt to acquire cookies or credentials from a Safari browser. Informational Platform Analytics Process execution Credential Access
Analytics Web server CGO executed a process following a potential Webshell dropped A process was executed by a web server CGO following a potential drop of a webshell file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. Informational Platform Analytics XDR Agent Initial Access, Persistence
BIOC Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. Informational Platform Analytics File Initial Access
BIOC Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. Informational Platform Analytics Process execution Initial Access
Analytics BIOC WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. Informational Platform Analytics XDR Agent Exfiltration
BIOC WerFault ReflectDebugger key set in Registry The WerFault.exe signed Windows process may be tricked into running a malicious executable by setting the ReflectDebugger key in the Registry. Medium Platform Analytics Registry Defense Evasion
BIOC Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. Informational Platform Analytics Network Exfiltration
BIOC Windows 10 Developer Mode enabled Enabling developer mode allows for app sideloading and starts the Windows SSH services, which may be used to install Linux Bash on Windows. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. Low Platform Analytics XDR Agent Impact
BIOC Windows event logs cleared using wmic.exe Attackers may clear events from Windows event logs to remove traces of their malicious activity. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Windows File Protection being disabled via Registry Windows File Protection (WFP) prevents programs from replacing critical Windows system files. Programs must not overwrite these files because they are used by the operating system and by other programs. Protecting these files prevents problems with programs and the operating system. Low Platform Analytics Registry Impact
BIOC Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. Informational Platform Analytics Registry Defense Evasion
BIOC Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. Informational Platform Analytics File Collection
Analytics BIOC Windows Installer exploitation for local privilege escalation The Windows installer (msiexec.exe) was likely exploited to run a malicious rollback script (.rbs file) instead of the original. Users should not be able to modify config.msi during the installation process, only SYSTEM should have access to it. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Windows LOLBIN executable connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Medium Platform Analytics XDR Agent Command and Control
BIOC Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. Informational Platform Analytics Registry Defense Evasion
BIOC Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. Informational Platform Analytics Process execution Defense Evasion
BIOC Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. Informational Platform Analytics Windows event log Defense Evasion
BIOC Windows set to permit unsigned drivers (Test Mode) This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers. Medium Platform Analytics Process execution Defense Evasion
BIOC Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. Informational Platform Analytics Registry Defense Evasion
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact
BIOC WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. Informational Platform Analytics Process execution Defense Evasion, Execution
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
BIOC WptsExtensions.dll created to disk The Task Scheduler service attempts to load the missing WptsExtensions.dll. As a result, the creation of this file may be indicative of DLL hijacking. Medium Platform Analytics File Privilege Escalation
BIOC Write to .bash_profile Commands in ~/.bash_profile are executed on every user shell login with a username and password. Informational Platform Analytics File Persistence
BIOC Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. Informational Platform Analytics File Discovery
BIOC Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Wscript.exe connects to an external network It may be due to local IT or administrative tools used on endpoints, but it could also indicate exfiltration of data between hosts in the local network, malware droppers, beaconing and so on. The execution chain should be reviewed to determine the context of the activity. Informational Platform Analytics Network Execution
Analytics BIOC Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. Low Platform Analytics XDR Agent Defense Evasion
BIOC WSL Feature Installation Detecting installation of Windows Subsystem for Linux feature. Informational Platform Analytics File Defense Evasion
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
BIOC WSReset.exe UAC bypass Attackers may use WSReset.exe to bypass User Account Control (UAC). Low Platform Analytics Process execution Privilege Escalation
BIOC Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection