Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. technique: T1548 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Bypassing Windows UAC using sysprep Attackers may use the sysprep.exe built-in Windows tools to bypass Windows UAC. Informational Platform Analytics Process execution Privilege Escalation
BIOC Command enumeration via sudo The 'sudo -l' command was executed to enumerate commands that can be executed by a user. Informational Platform Analytics Process execution Privilege Escalation
Analytics BIOC Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
BIOC Discovery of files with setgid or setuid bits Attackers may try to locate files with setgid or setuid bits set to escalate privileges. Informational Platform Analytics Process execution Privilege Escalation
BIOC Manipulation of MMC Registry configuration Creation or modification of these Microsoft Management Console related entries can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics Registry Privilege Escalation
BIOC Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. Informational Platform Analytics Process execution Privilege Escalation
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
Analytics BIOC Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. Informational Platform Analytics Process execution Privilege Escalation