Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
138 detectors match the current filters. tactic: TA0002 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | 64-bit PowerShell spawning a 32-bit PowerShell Malware typically spawns 32-bit processes to work on as many hosts as possible. This case is therefore suspicious when it happens on a 64-bit host. | Low | Platform Analytics | Process execution | Execution |
| Analytics BIOC | A remote service was created via RPC over SMB A remote service was created via RPC over SMB. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| BIOC | A scripting engine was called to run in command line Scripting engines that are called to run in command line are used by attackers to run a script payload without a UI. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | A suspicious direct syscall was executed A suspicious direct syscall was executed. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Defense Evasion |
| Analytics BIOC | A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics | Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics BIOC | Adding execution privileges A script was granted execution privileges using chmod before being run. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics | AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| BIOC | An executable compiled with a py2exe-like program was executed A py2exe-like program DLL file dropped to disk. | Informational | Platform Analytics | File | Execution |
| Analytics BIOC | AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. | High | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Correlation Rule | Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. | Medium | Platform Analytics | google_workspace_chrome_raw | Execution |
| Analytics BIOC | ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Initial Access |
| Analytics BIOC | Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command execution via wmiexec Attackers may use WMI to execute commands on the target host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. | Medium | Platform Analytics | XDR Agent | Exfiltration, Execution |
| Analytics BIOC | Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| BIOC | Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. | Informational | Platform Analytics | Process execution | Lateral Movement, Execution |
| Analytics BIOC | Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Commonly abused process launches as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Commonly abused process spawns from Scripted Diagnostics Host This Scripted Diagnostics Host (sdiagnhost.exe) process has been observed launching a commonly abused host process. This behavior is known to be associated with an exploitation technique designed to deliver a malicious payload, often via a weaponized document. https://www.proofpoint.com/us/threat-insight/post/windows-troubleshooting-platform-leveraged-deliver-malware. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Download a script using the python requests module Download a shell script from a remote location using the Python requests module. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics BIOC | Elevation to SYSTEM via services Services were affected by a non SYSTEM integrity level process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Privilege Escalation |
| BIOC | Encoded VBScript executed Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding. | High | Platform Analytics | Process execution | Execution, Defense Evasion |
| BIOC | Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Fontdrvhost.exe makes network connections A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation. | Informational | Platform Analytics | Network | Execution |
| Analytics BIOC | Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Interactive at.exe privilege escalation method Detects an interactive AT scheduled task, which may be used as a form of privilege escalation. | Low | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Known service display name with uncommon image-path Service created with a known display name but has an uncommon image-path. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Execution |
| Analytics BIOC | Known service name with an uncommon image-path A Service with a known service name has an uncommon image-path. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Execution |
| Analytics BIOC | Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. | Medium | Platform Analytics | XDR Agent | Execution, Discovery |
| Analytics BIOC | Linux process execution with a rare GitHub URL A process was executed with an uncommon GitHub URL in its command line. This may have legitimate uses, but it might also be used by attackers to download malicious payloads. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| BIOC | Malicious NetSetupSvc.dll loaded into svchost.exe A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe. | Informational | Platform Analytics | Module | Execution |
| BIOC | Manipulation of Windows DNS configuration using WMIC This command can be leveraged by attackers to change the way DNS requests are sent, bypassing the corporate DNS servers. | Low | Platform Analytics | Process execution | Execution |
| BIOC | Microsoft Office Equation Editor spawns a commonly abused process A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. CVE-2017-11882 Microsoft Office Memory Corruption Vulnerability. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Microsoft Office executes an unsigned process in a suspicious directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| BIOC | Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Microsoft Office process spawns an unsigned process Common weaponized office document behavior. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics | Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| BIOC | Netcat shell via named pipe Attackers may create a Netcat shell using a named pipe to remotely access the endpoint. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Persistence |
| BIOC | Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. | Informational | Platform Analytics | File | Execution |
| BIOC | Perl script connecting to network Perl scripts may be used by attackers to connect to their command-and-control infrastructure. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| BIOC | PowerShell calling Invoke-Expression argument These PowerShell arguments are often used to run commands with malicious intent. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | PowerShell Initiates a Network Connection to GitHub PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads. | Low | Platform Analytics | Palo Alto Networks Url Logs | Execution |
| BIOC | PowerShell possibly attempting to execute as administrator This PowerShell argument is often used to run commands with malicious intent. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | PowerShell reverse shell This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell. | Medium | Platform Analytics | Network | Execution |
| BIOC | PowerShell running with download in the command line PowerShell can be used to download malicious content from the internet. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. | High | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| BIOC | Process calls ActiveX Object with a shell command This rule looks for ActiveX being used to run commands on a machine, seen in cases of evasive attacks. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Process runs with a double extension Look for executables with a common double extension. These are often used to disguise malware as some form of user content. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. | Informational | Platform Analytics | Network | Lateral Movement, Execution |
| BIOC | PsExec executed with plain-text credentials on the command line PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. | Informational | Platform Analytics | Registry | Lateral Movement, Execution |
| Analytics BIOC | PsExec was executed with a suspicious command line PsExec.exe was executed. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| BIOC | Psexesvc.exe executes a command from a remote host Psexesvc.exe executes to run a command received from a remote host via PsExec. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Python script connecting to network Python scripts may be used by attackers to connect to their command-and-control infrastructure. | Medium | Platform Analytics | Process execution | Execution |
| BIOC | Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| Analytics BIOC | Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Remote command executed from a Linux host This tool enables commands to be remotely executed on a Microsoft Windows computer from a Linux computer. This capability is leveraged by attackers to run code remotely, similarly to PsExec. | Low | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| BIOC | Reverse shell one-liner using a scripting engine An attacker may use scripting engines to execute code from the command line to open a reverse shell. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Reverse shell using PowerShell PowerShell can start a reverse shell console for attackers using these commands and take control of the machine. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Scheduled task created with HTTP or FTP reference Scheduled tasks don't normally include web URLs and may indicate malware activity. | Low | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. | Informational | Platform Analytics | XDR Agent | Execution |
| BIOC | Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| Analytics BIOC | Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| BIOC | Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by Cymulate Simulation activity performed by Cymulate agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| BIOC | Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. | Informational | Platform Analytics | File | Execution, Resource Development |
| Analytics BIOC | Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. | Low | Platform Analytics | XDR Agent | Execution, Persistence, Privilege Escalation |