Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. tactic: TA0003 ✕ technique: T1098 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
BIOC New local user created via PowerShell command line Attackers may create new local users to persist access to machines. Medium Platform Analytics Process execution Persistence
Analytics BIOC Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. Low Platform Analytics XDR Agent Persistence
BIOC User added to local administrator group using a PowerShell command Adding a new user to the local admin group may or may not be malicious, but it is an outstanding action worth considering, as it shouldn't happen too often. A malware may add a new malicious user to the administrators group as a way of maintaining high privileges after the system was compromised. Medium Platform Analytics Process execution Persistence