Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
38 detectors match the current filters. tactic: TA0005 ✕ technique: T1562 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Chrome launched in Incognito mode May be used to cover up malware or malicious insider activity. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Clear event logging policy using auditpol.exe Attackers may clear Windows Event Logging policies using auditpol.exe. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Disable outlook security via Registry Attackers may try to disable outlook security features by modifying the Registry. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Disabling Windows Defender via Registry Windows Defender stores its configuration in the Registry. By modifying these values, an attacker can disable security features. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | EventLog service disabled by a Registry operation A Registry set-value operation that disables the EventLog service was executed on the machine. | High | Platform Analytics | Registry | Defense Evasion |
| BIOC | Fltmc.exe used to unload filter driver Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Indicator blocking Auditing or logging configuration changes on Linux host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Internet Explorer security settings modification The Security Settings Check feature, which checks Internet Explorer security settings to determine risk, was disabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | Iptables configuration command was executed The iptables process was executed with a command to add or delete rules on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Linux system firewall was modified The system firewall was modified. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | MacOS firewall manipulation An attacker may modify a firewall via command line to bypass network controls. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Manipulation of Windows Defender configuration Commands used to bypass, disable or harm Windows Defender. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Manipulation of Windows Event Log auto-backup via Registry This key enables/disables the automatic backups of event logs when they are full. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Netsh.exe modifies allowed firewall port/program lists Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Process attempts to kill a known security/AV tool This process has attempted to use taskkill.exe to terminate a known AV process or security analysis tool. Likely attempt to evade detection. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Security services stopped Attackers may stop security critical services to avoid possible detection of their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | SELinux was set to permissive mode SELinux was set to permissive mode using the "setenforce 0" command. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | SmartScreen disabled via Registry These Registry keys control the SmartScreen. Malware may turn it off to evade SmartScreen functionality. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Suspicious AMSI DLL load location An attacker may attempt to load a malicious copy of amsi.dll to bypass Microsoft's Antimalware Scan Interface (AMSI). | Low | Platform Analytics | Module | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |
| BIOC | Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | The Linux system firewall was disabled The system firewall was disabled. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| BIOC | Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows set to permit unsigned drivers (Test Mode) This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. | Informational | Platform Analytics | Process execution | Defense Evasion, Execution |