Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
130 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation, Persistence |
| Analytics | A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Impact |
| Analytics BIOC | A process was executed with a command line obfuscated by Unicode character substitution A process was executed with a command line obfuscated by Unicode character substitution. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Defense Evasion |
| Analytics BIOC | A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. | Medium | Platform Analytics | XDR Agent | Execution |
| Correlation Rule | Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account | Medium | Platform Analytics | alibaba_action_trail_raw | |
| BIOC | AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics | An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. | Medium | Platform Analytics | XDR Agent | Persistence, Defense Evasion |
| Analytics BIOC | Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. | Medium | Platform Analytics | XDR Agent | Persistence, Lateral Movement |
| Analytics BIOC | Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. | Medium | Platform Analytics | XDR Agent | Persistence |
| BIOC | Bypass UAC using the control.exe Registry key Control.exe is a Registry key known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Bypass UAC using the IsolatedCommand Registry value IsolatedCommand is a Registry value known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| Correlation Rule | Chrome - Known Malicious Site Visit Unsafe site $xdm.network.http.url was visited by $xdm.source.user.username via chrome profile $xdm.intermediate.user.username. | Medium | Platform Analytics | google_workspace_chrome_raw | |
| Correlation Rule | Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. | Medium | Platform Analytics | google_workspace_chrome_raw | Execution |
| Correlation Rule | Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. | Medium | Platform Analytics | google_workspace_chrome_raw | Initial Access |
| BIOC | Clear logs - using dd and /dev/null Usage of the dd utility to clear the contents of a file using /dev/null. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. | Medium | Platform Analytics | XDR Agent | Exfiltration, Execution |
| Analytics BIOC | Correlation rule error An error was identified while running a correlation rule. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. | Medium | Platform Analytics | Process execution | Credential Access |
| Correlation Rule | CyberArk Failed Logins This correlation rule will trigger in an event in which 4 or more Failed Logins events occurred from a single user during a 10 minutes timeframe. | Medium | Platform Analytics | cyberark_identity_raw | |
| BIOC | Delete Volume USN Journal with fsutil This technique is used by attackers to eliminate evidence of files created during post-exploitation activities. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | DNS reconnaissance or enumeration via DNSRecon DNSRecon enables DNS reconnaissance and enumeration, and may be used by attackers to learn about targets' network infrastructure. | Medium | Platform Analytics | Process execution | Discovery |
| Correlation Rule | DropBox - Massive File Downloads This rule detects more than 100 downloaded files during an hour by the same user. This is a suspicious behavior which can be an indication of a data exfiltration. | Medium | Platform Analytics | dropbox_dropbox_raw | Exfiltration |
| BIOC | Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Error in event forwarding An error was detected in event forwarding. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Executable created to disk by lsass.exe Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| Analytics BIOC | Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Correlation Rule | Gitlab - User Permission Changed User''s permissions have changed from Guest to Owner | Medium | Platform Analytics | gitlab_gitlab_raw | |
| BIOC | Gost tunneling execution Possible use of Gost (tunnel written in Golang) SSH tunnel. | Medium | Platform Analytics | Process execution | Command and Control |
| BIOC | Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | Impersonation using Rubeus tool User authentication should not be impersonated, since this is considered a malicious behavior. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Indirect command execution using the Program Compatibility Assistant Pcalua.exe (Program Compatibility Assistant) is used for running old programs that have compatibility issues. Attackers can use pcalua.exe to indirectly execute their malicious programs. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Kerberos ticket forging using Impacket ticketer Suspected execution of Impacket's ticketer.py script for forging TGT/TGS Kerberos tickets. | Medium | Platform Analytics | Process execution | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Kerberos Traffic from Non-Standard Process The endpoint had a non-standard process communicating over ports normally used by Kerberos. An attacker might be using malicious tools to move laterally. | Medium | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. | Medium | Platform Analytics | XDR Agent | Execution, Discovery |
| Analytics BIOC | LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| BIOC | Manipulation of Firefox plugins and extensions via the Registry Plugins and extensions are loaded from all of these Registry keys. | Medium | Platform Analytics | Registry | Persistence |
| Analytics BIOC | Manipulation of netsh helper DLLs Registry keys Registering netsh helper DLLs is uncommon, and could be used by malware for persistence. | Medium | Platform Analytics | XDR Agent | Persistence |
| BIOC | Manipulation of the MonitorProcess Registry key Entries added under the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit can be used to run malicious code and help attackers gain persistence. | Medium | Platform Analytics | Registry | Persistence |
| BIOC | Manipulation of the sticky keys file Possible login bypass attack. | Medium | Platform Analytics | File | Privilege Escalation |
| BIOC | Manipulation of Windows Safe Boot configuration Safe-boot Registry settings deletion. | Medium | Platform Analytics | Registry | Impact |
| BIOC | Manipulation of Winlogon 'UserInit' autostart Registry key Winlogon process uses the value specified in the UserInit key to launch login scripts etc. This key is location at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. Usually, UserInit key points to userinit.exe but if this key can be altered, then that EXE will also launch by Winlogon. | Medium | Platform Analytics | Registry | Persistence |
| BIOC | Microsoft Office Equation Editor spawns a commonly abused process A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. CVE-2017-11882 Microsoft Office Memory Corruption Vulnerability. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Modification of logon scripts via Registry Windows logon scripts are stored in ``HKCU\Environment\UserInitMprLogonScript`` and trigger when a user logs in. Attackers may abuse them for persistence. | Medium | Platform Analytics | Registry | Persistence |
| BIOC | Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. | Medium | Platform Analytics | Registry | Persistence, Lateral Movement |
| Analytics | New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| BIOC | New local user created via PowerShell command line Attackers may create new local users to persist access to machines. | Medium | Platform Analytics | Process execution | Persistence |
| BIOC | NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Parsing Rule Error A Parsing Rule error was detected. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Perl script connecting to network Perl scripts may be used by attackers to connect to their command-and-control infrastructure. | Medium | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Phantom DLL Loading An attacker might leverage existing processes missing module loads to load malicious code into trusted processes. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. | Medium | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. | Medium | Platform Analytics | XDR Agent | Execution |
| BIOC | Possible Firefox browser history and bookmarks collection via command-line tool Attackers may collect history and bookmarks details by accessing the Firefox database. | Medium | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible malicious .NET compilation started by a commonly abused process Attackers may use csc.exe to compile payloads on a compromised machine. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible Persistence via group policy Registry keys Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| BIOC | Possible ping sweep Ping sweeps are useful tools that can detect which machines are up in the network and can be the step before lateral movement. | Medium | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible RDP session hijacking using tscon.exe The executable tscon.exe can be used to hijack other sessions on the same computer. The attacker may use another user's credentials to proceed with the lateral movement or disguise the activity. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Possible Search For Password Files Attackers often search for files that have passwords in them. | Medium | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Possible UAC bypass via Event Viewer Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | PowerShell downloads files via BITS This PowerShell argument is often used to run commands with malicious intent. | Medium | Platform Analytics | Process execution | Persistence |
| BIOC | PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | PowerShell reverse shell This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell. | Medium | Platform Analytics | Network | Execution |
| BIOC | PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. | Medium | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Credential Access |
| BIOC | Process attempts to kill a known security/AV tool This process has attempted to use taskkill.exe to terminate a known AV process or security analysis tool. Likely attempt to evade detection. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Process calls ActiveX Object with a shell command This rule looks for ActiveX being used to run commands on a machine, seen in cases of evasive attacks. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Process changes the Windows logon text This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user. | Medium | Platform Analytics | Registry | Impact |
| BIOC | Process runs with a double extension Look for executables with a common double extension. These are often used to disguise malware as some form of user content. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Python script connecting to network Python scripts may be used by attackers to connect to their command-and-control infrastructure. | Medium | Platform Analytics | Process execution | Execution |
| Analytics | Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics BIOC | RDP Connection to localhost An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Remote WMI process execution A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| BIOC | Rundll32.exe launches an executable using ordinal numbers argument Rundll32.exe launches an executable using ordinal numbers argument, this behavior may be used by attackers to evade detection. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Rundll32.exe was used to run JavaScript Attackers may execute malicious JavaScript code (either remotely or locally) using rundll32.exe. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Rundll32.exe with 'main' as EntryPoint Rundll32.exe ran with 'main' as EntryPoint. Attackers may leverage rundll32.exe to execute malicious functions and DLLs. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Script file added to startup-related Registry keys An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. | Medium | Platform Analytics | XDR Agent | Persistence |
| BIOC | SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. | Medium | Platform Analytics | Windows event log | Discovery |
| BIOC | Socat/Netcat connects to TOR domain Unlikely behavior in standard systems. | Medium | Platform Analytics | Network | Command and Control |
| Analytics | Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious authentication package registered The endpoint registered a suspicious authentication package, which may be used to gain persistence on the host by loading libraries into the time management service. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious certutil command line An attacker may use certutil to download malware. | Medium | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |