Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
12 detectors match the current filters. technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics BIOC | Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Microsoft Office process spawns an unsigned process Common weaponized office document behavior. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. | Informational | Platform Analytics | File | Execution |
| BIOC | Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by Cymulate Simulation activity performed by Cymulate agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| Analytics BIOC | Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. | Informational | Platform Analytics | XDR Agent | Execution |