Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
50 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A compiled HTML help file wrote a script file to the disk A compiled HTML help file wrote a script file to the disk. Compiled HTLM help files usually don't write script files to the disk. This behavior is often employed by malware that leverages malicious CHM files to deliver a 2nd stage payload. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Accessing bash history file Clearing bash history file is a known procedure of attackers to delete traces. | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Accessing bash history file using bash commands Clearing bash history files is a known attacker procedure for covering their tracks. | Low | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | DLL sideloading attack using Xwizard Xwizard has a known DLL-sideloading vulnerability, which involves moving the legitimate Xwizard.exe file into a new directory along with a malicious Xwizard.dll file. This is a possible indicator of an attacker preparing to execute a DLL-sideloading attack. | Low | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Execution of dllhost.exe with an empty command line The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Linux system firewall was modified The system firewall was modified. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Masquerading as the Linux crond process Copies a file and renames it as crond. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Microsoft Connection Manager Profile Installer loads a file from the users to temporary folder The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other whitelisting defenses since CMSTP.exe is a legitimate, signed Microsoft application. | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Microsoft Connection Manager Profile Installer makes connections to the network The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other whitelisting defenses since CMSTP.exe is a legitimate, signed Microsoft application. | Low | Platform Analytics | Network | Defense Evasion |
| BIOC | Microsoft Connection Manager Profile Installer runs command line or PowerShell The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line program used to install Connection Manager service profiles. CMSTP.exe may be abused to load and execute DLLs and/or COM scriptlets (SCT) from remote servers. This execution may also bypass AppLocker and other whitelisting defenses since CMSTP.exe is a legitimate, signed Microsoft application. | Low | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Microsoft Office injects code into a process An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways. | Low | Platform Analytics | XDR Agent | Initial Access, Defense Evasion |
| Analytics BIOC | Mshta.exe launched with suspicious arguments Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Mshta.exe spawns from a browser process Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Notepad process makes a network connection Notepad.exe processes should not normally make network connections (with the occasional exception of printing documents). This can be a possible indicator of exploitation, e.g. Metasploit Meterpreter injection. | Low | Platform Analytics | Network | Defense Evasion |
| Analytics BIOC | Office process spawned with suspicious command-line arguments An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| BIOC | Process runs from the recycle bin Process running from the recycle bin. | Low | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Rare security product signed executable executed in the network Attackers may attempt to install a security product with a known vulnerability to bypass security features. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Persistence |
| Analytics BIOC | Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| BIOC | Suspicious .NET process spawns csc.exe A suspicious process in the Microsoft .NET directory spawned the C# compiler. This may occur if an attacker masquerades a process like MSBuild (e.g. PowerLessShell). | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Suspicious AMSI DLL load location An attacker may attempt to load a malicious copy of amsi.dll to bypass Microsoft's Antimalware Scan Interface (AMSI). | Low | Platform Analytics | Module | Defense Evasion |
| Analytics BIOC | Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. | Low | Platform Analytics | XDR Agent | Impact, Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious DotNet log file created Payloads that use the DotNet framework may generate suspicious Microsoft DotNet log files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |
| Analytics BIOC | Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. | Low | Platform Analytics | XDR Agent | Defense Evasion, Persistence |
| BIOC | Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. | Low | Platform Analytics | Registry | Defense Evasion, Impact |
| Analytics BIOC | The Linux system firewall was disabled The system firewall was disabled. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. | Low | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon execution of ODBCConf Attackers may abuse the Odbcconf.exe Windows utility to proxy the execution of malicious DLL files. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| Analytics BIOC | Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |