Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

74 detectors match the current filters. tactic: TA0007 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
BIOC ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). Informational Platform Analytics Process execution Discovery
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Container enumeration An attacker may run a command to enumerate containers on a machine. Informational Platform Analytics Process execution Discovery
Analytics BIOC Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent Discovery
BIOC Document discovery Attackers may use the find command to look for documents. Informational Platform Analytics Process execution Discovery
BIOC Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. Informational Platform Analytics Process execution Discovery, Execution
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
BIOC Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. Informational Platform Analytics Process execution Defense Evasion, Discovery
BIOC Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. Informational Platform Analytics Process execution Discovery
BIOC Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. Informational Platform Analytics Process execution Discovery
BIOC Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. Informational Platform Analytics Process execution Discovery
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. Informational Platform Analytics XDR Agent Discovery
BIOC Linux network share discovery A Linux network share discovery command was executed. Informational Platform Analytics Process execution Discovery
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local group enumeration via RPC A user enumerated local groups via RPC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Local user enumeration via SAMR A user enumerated local users via SAMR. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. Informational Platform Analytics Process execution Discovery
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
BIOC Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. Informational Platform Analytics Process execution Discovery
BIOC Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. Informational Platform Analytics Process execution Discovery
BIOC Password complexity enumeration Attackers may read system files containing password complexity requirements. Informational Platform Analytics Process execution Discovery
BIOC Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. Informational Platform Analytics Process execution Discovery
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
BIOC Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. Informational Platform Analytics Process execution Discovery
Analytics Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls Discovery
Analytics Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
BIOC Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). Informational Platform Analytics Process execution Discovery
BIOC Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. Informational Platform Analytics Process execution Discovery
Analytics Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
BIOC Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. Informational Platform Analytics Process execution Discovery
BIOC Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. Informational Platform Analytics Process execution Discovery
BIOC Potential Network Sniffing Network sniffing related processes were detected. Informational Platform Analytics Process execution Credential Access, Discovery
BIOC Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. Informational Platform Analytics Process execution Discovery, Execution
BIOC Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. Informational Platform Analytics Process execution Discovery
BIOC Remote system discovery Remote system discovery using a system utility. Informational Platform Analytics Process execution Discovery
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
BIOC Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. Informational Platform Analytics Process execution Discovery, Execution
BIOC SMB enumeration via command-line tool Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources. Informational Platform Analytics Process execution Discovery
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
BIOC Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. Informational Platform Analytics File Discovery
Analytics Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious PowerShell Enumeration of Running Processes Attackers often enumerate running processes to find and disable security tools. Informational Platform Analytics XDR Agent Discovery
Analytics Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. Informational Platform Analytics Process execution Discovery
BIOC System network configuration discovery System network configuration discovery using Linux command-line utilities. Informational Platform Analytics Process execution Discovery
BIOC System owner/user discovery System owner/user discovery using bash utilities. Informational Platform Analytics Process execution Discovery
Analytics BIOC System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
BIOC VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. Informational Platform Analytics Process execution Discovery
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. Informational Platform Analytics XDR Agent Defense Evasion, Discovery
BIOC VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. Informational Platform Analytics Process execution Discovery
BIOC Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. Informational Platform Analytics File Discovery