Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

15 detectors match the current filters. technique: T1036 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Common Apple process name missing Apple digital signature These common Apple process names should normally be signed with the Apple Inc. digital signature. Naming processes with common names is a common way attackers obfuscate their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Common Mozilla process name missing Mozilla digital certificate These common Mozilla process names should normally be signed with the Mozilla Corporation digital signature. Naming processes with common names is a common way attackers obfuscate their activities. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. Informational Platform Analytics XDR Agent Defense Evasion
BIOC File renamed to have a script extension Adversaries may create 'benign-looking' files, which are later used as malicious scripts by changing their extension. Informational Platform Analytics File Defense Evasion
BIOC Shell binary copied to another location Attackers may try to evade detection by copying the shell binary to an innocent-looking name. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. Informational Platform Analytics File Defense Evasion
Analytics BIOC Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. Informational Platform Analytics XDR Agent Command and Control, Defense Evasion
BIOC Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. Informational Platform Analytics Process execution Defense Evasion