Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics BIOC | ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Initial Access |
| Analytics BIOC | Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics | Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics BIOC | Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Persistence |
| Analytics BIOC | Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Low | Platform Analytics | XDR Agent | Execution |