Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. tactic: TA0040 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Broker Collection Error A collection error was detected on a broker VM. | Informational | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| BIOC | Manipulation of permissions for the Application Event Log Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx. | Informational | Platform Analytics | Registry | Impact |
| BIOC | Manipulation of Volume Shadow Copy configuration Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy. | Informational | Platform Analytics | Registry | Impact |
| BIOC | Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| BIOC | Possible data destruction via dd Attackers may use dd to zero out or write random data to files. | Informational | Platform Analytics | Process execution | Impact |
| BIOC | Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. | Informational | Platform Analytics | Process execution | Impact |
| Analytics BIOC | System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. | Informational | Platform Analytics | XDR Agent | Impact |
| BIOC | WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. | Informational | Platform Analytics | Process execution | Credential Access, Impact |