Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

21 detectors match the current filters. tactic: TA0009 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
BIOC Built-in SoundRecorder tool capturing audio SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user. Informational Platform Analytics Process execution Collection
BIOC Command-line creation of a RAR archive Compression of data into a RAR archive using the rar.exe utility. Informational Platform Analytics Process execution Collection
BIOC Compressed archive created using tar Attackers may use the tar built-in tool to stage a file for exfiltration. Informational Platform Analytics Process execution Collection
BIOC Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. Informational Platform Analytics Process execution Collection
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
Analytics BIOC Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. Informational Platform Analytics XDR Agent Collection
BIOC PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
BIOC Screen capture via command-line tool Attackers may use the window system screen capture tool to collect screenshots. Informational Platform Analytics Process execution Collection
BIOC Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. Informational Platform Analytics File Collection
BIOC Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. Informational Platform Analytics File Collection
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics File Credential Access, Collection
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics Process execution Credential Access, Collection
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. Informational Platform Analytics File Collection
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection