Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
74 detectors match the current filters. tactic: TA0007 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| BIOC | Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. | Informational | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Container enumeration An attacker may run a command to enumerate containers on a machine. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Document discovery Attackers may use the find command to look for documents. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. | Informational | Platform Analytics | Dml connection | Discovery |
| BIOC | Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. | Informational | Platform Analytics | Process execution | Defense Evasion, Discovery |
| BIOC | Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. | Informational | Platform Analytics | XDR Agent | Privilege Escalation, Discovery |
| Analytics BIOC | Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Linux network share discovery A Linux network share discovery command was executed. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Local account discovery One of several local account discovery commands were executed. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Local group enumeration via RPC A user enumerated local groups via RPC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Local user enumeration via SAMR A user enumerated local users via SAMR. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Password complexity enumeration Attackers may read system files containing password complexity requirements. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Permission Groups discovery commands Permission group discovery command execution. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls | Discovery |
| Analytics | Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| BIOC | Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| BIOC | Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |
| BIOC | Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Remote system discovery Remote system discovery using a system utility. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| BIOC | Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | SMB enumeration via command-line tool Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| BIOC | Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. | Informational | Platform Analytics | File | Discovery |
| Analytics | Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Suspicious PowerShell Enumeration of Running Processes Attackers often enumerate running processes to find and disable security tools. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System network configuration discovery System network configuration discovery using Linux command-line utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System owner/user discovery System owner/user discovery using bash utilities. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Discovery |
| Analytics | User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Discovery |
| BIOC | VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | VM Detection attempt A script has executed commands that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Discovery |
| BIOC | VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. | Informational | Platform Analytics | File | Discovery |