Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

68 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC A scripting engine was called to run in command line Scripting engines that are called to run in command line are used by attackers to run a script payload without a UI. Informational Platform Analytics Process execution Execution
Analytics BIOC Adding execution privileges A script was granted execution privileges using chmod before being run. Informational Platform Analytics XDR Agent Execution
Analytics AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
BIOC An executable compiled with a py2exe-like program was executed A py2exe-like program DLL file dropped to disk. Informational Platform Analytics File Execution
Analytics BIOC AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command execution via wmiexec Attackers may use WMI to execute commands on the target host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
BIOC Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. Informational Platform Analytics Process execution Lateral Movement, Execution
Analytics BIOC Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. Informational Platform Analytics XDR Agent Execution
BIOC Commonly abused process launches as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. Informational Platform Analytics Process execution Execution
BIOC Commonly abused process spawns from Scripted Diagnostics Host This Scripted Diagnostics Host (sdiagnhost.exe) process has been observed launching a commonly abused host process. This behavior is known to be associated with an exploitation technique designed to deliver a malicious payload, often via a weaponized document. https://www.proofpoint.com/us/threat-insight/post/windows-troubleshooting-platform-leveraged-deliver-malware. Informational Platform Analytics Process execution Execution
Analytics BIOC DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
BIOC Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. Informational Platform Analytics Process execution Discovery, Execution
BIOC Fontdrvhost.exe makes network connections A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Network Execution
Analytics BIOC Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. Informational Platform Analytics XDR Agent Execution
Analytics BIOC LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
BIOC Malicious NetSetupSvc.dll loaded into svchost.exe A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe. Informational Platform Analytics Module Execution
BIOC Microsoft Office executes an unsigned process in a suspicious directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns an unsigned process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Netcat shell via named pipe Attackers may create a Netcat shell using a named pipe to remotely access the endpoint. Informational Platform Analytics Process execution Execution
BIOC Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. Informational Platform Analytics File Execution
BIOC PowerShell calling Invoke-Expression argument These PowerShell arguments are often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
BIOC PowerShell possibly attempting to execute as administrator This PowerShell argument is often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
BIOC PowerShell running with download in the command line PowerShell can be used to download malicious content from the internet. Informational Platform Analytics Process execution Execution
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec executed with plain-text credentials on the command line PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands. Informational Platform Analytics Process execution Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
BIOC Psexesvc.exe executes a command from a remote host Psexesvc.exe executes to run a command received from a remote host via PsExec. Informational Platform Analytics Process execution Execution
BIOC Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. Informational Platform Analytics Process execution Discovery, Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Reverse shell one-liner using a scripting engine An attacker may use scripting engines to execute code from the command line to open a reverse shell. Informational Platform Analytics Process execution Execution
BIOC Reverse shell using PowerShell PowerShell can start a reverse shell console for attackers using these commands and take control of the machine. Informational Platform Analytics Process execution Execution
Analytics BIOC Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. Informational Platform Analytics XDR Agent Execution
BIOC Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. Informational Platform Analytics Process execution Discovery, Execution
Analytics BIOC Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. Informational Platform Analytics XDR Agent Execution, Persistence
BIOC Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by Cymulate Simulation activity performed by Cymulate agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. Informational Platform Analytics File Execution, Resource Development
Analytics BIOC Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. Informational Platform Analytics XDR Agent Execution
BIOC Suspicious file created in AppData directory A suspicious executable file was created in the AppData directory. Informational Platform Analytics File Execution
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. Informational Platform Analytics XDR Agent Execution
BIOC Suspicious process loads AMSI DLL Amsi.dll is expected to be loaded from a few known processes (e.g. PowerShell). An image load from an unrelated LOLBIN may indicate PowerShell execution. Informational Platform Analytics Module Execution
Analytics BIOC System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent Execution
BIOC Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Process execution Execution
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
BIOC VBScript execution from the command line Attackers may run VBScript code from the command line using signed processes such as Mshta. Informational Platform Analytics Process execution Execution
Analytics BIOC Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
BIOC WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. Informational Platform Analytics Process execution Defense Evasion, Execution
BIOC Wscript.exe connects to an external network It may be due to local IT or administrative tools used on endpoints, but it could also indicate exfiltration of data between hosts in the local network, malware droppers, beaconing and so on. The execution chain should be reviewed to determine the context of the activity. Informational Platform Analytics Network Execution