Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
4 detectors match the current filters. tactic: TA0007 ✕ technique: T1040 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |