Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
18 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| BIOC | Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. | Informational | Platform Analytics | Process execution | Initial Access |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| BIOC | Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. | Informational | Platform Analytics | File | Initial Access |
| Analytics BIOC | Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access |
| BIOC | Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. | Informational | Platform Analytics | File | Initial Access |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Rare MS-Update Server was detected The endpoint requested an MS-Update operation from a rare update server. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. | Informational | Platform Analytics | XDR Agent | Initial Access, Lateral Movement |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |
| BIOC | Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. | Informational | Platform Analytics | Process execution | Initial Access |