Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. tactic: TA0006 ✕ technique: T1110 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| Analytics BIOC | FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Kerberos brute-force attack using Kerbrute This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks. | Informational | Platform Analytics | Process execution | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. | Low | Platform Analytics | XDR Agent | Credential Access |