Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

8 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Internet Explorer home page modification The Internet Explorer home page could be changed to a malicious page. Low Platform Analytics Registry Impact, Credential Access
Analytics Logs were not collected from a data source for an abnormally long time Logs were not collected from a data source for an abnormally long time. Low Platform Analytics Health Monitoring Data Impact
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics BIOC Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. Low Platform Analytics XDR Agent Impact, Defense Evasion
Analytics Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. Low Platform Analytics XDR Agent Impact
BIOC Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. Low Platform Analytics Registry Defense Evasion, Impact
Analytics BIOC Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. Low Platform Analytics XDR Agent Impact
BIOC Windows File Protection being disabled via Registry Windows File Protection (WFP) prevents programs from replacing critical Windows system files. Programs must not overwrite these files because they are used by the operating system and by other programs. Protecting these files prevents problems with programs and the operating system. Low Platform Analytics Registry Impact