Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

18 detectors match the current filters. tactic: TA0001 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
BIOC Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. Informational Platform Analytics File Initial Access
BIOC Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. Informational Platform Analytics Process execution Initial Access
Analytics Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
BIOC Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. Informational Platform Analytics File Initial Access
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
BIOC Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. Informational Platform Analytics Process execution Initial Access
BIOC Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. Informational Platform Analytics Process execution Initial Access
BIOC Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. Informational Platform Analytics File Initial Access
Analytics BIOC Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Possible use of IPFS was detected The host produced traffic consistent with IPFS. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Rare MS-Update Server was detected The endpoint requested an MS-Update operation from a rare update server. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access
Analytics BIOC Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access
Analytics BIOC Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. Informational Platform Analytics XDR Agent Initial Access, Lateral Movement
Analytics Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
Analytics BIOC Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. Informational Platform Analytics XDR Agent Initial Access, Persistence
BIOC Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. Informational Platform Analytics File Initial Access
BIOC Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. Informational Platform Analytics Process execution Initial Access