Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Broker Collection Error A collection error was detected on a broker VM. Informational Platform Analytics Health Monitoring Data Impact
BIOC Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. Informational Platform Analytics Process execution Defense Evasion, Impact
BIOC Manipulation of permissions for the Application Event Log Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx. Informational Platform Analytics Registry Impact
BIOC Manipulation of Volume Shadow Copy configuration Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy. Informational Platform Analytics Registry Impact
BIOC Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. Informational Platform Analytics Process execution Defense Evasion, Impact
BIOC Possible data destruction via dd Attackers may use dd to zero out or write random data to files. Informational Platform Analytics Process execution Impact
BIOC Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. Informational Platform Analytics Process execution Impact
Analytics BIOC System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. Informational Platform Analytics XDR Agent Impact
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact