Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Bitsadmin.exe used to upload data Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools. High Platform Analytics Process execution Exfiltration, Defense Evasion
BIOC Encoded VBScript executed Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding. High Platform Analytics Process execution Execution, Defense Evasion
BIOC EventLog service disabled by a Registry operation A Registry set-value operation that disables the EventLog service was executed on the machine. High Platform Analytics Registry Defense Evasion
BIOC Pubprn.vbs signed script proxy execution Pubprn.vbs is a standard script that is installed with Windows that can be abused to run malicious scripts. This behavior may bypass signature validation restrictions and application whitelisting solutions. High Platform Analytics Process execution Defense Evasion
BIOC Regsvr32 may have run code from an untrusted source Regsvr32 may be used to run arbitrary code by passing the '/i' parameter. The code may also be hosted on a remote host. High Platform Analytics Process execution Defense Evasion
BIOC Suspicious executable created in a .NET directory Cmd.exe created an executable file in the Microsoft .NET directory. This behavior is exhibited in the PowerLessShell tool to disguise MSBuild.exe. High Platform Analytics File Defense Evasion
Analytics BIOC Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. High Platform Analytics XDR Agent Defense Evasion