Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

39 detectors match the current filters. tactic: TA0009 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Built-in SoundRecorder tool capturing audio SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user. Informational Platform Analytics Process execution Collection
Analytics BIOC Certutil pfx parsing Certutil was used to parse a pfx certificate file. Low Platform Analytics XDR Agent Collection
BIOC Collecting audio via PowerShell command An attacker may collect audio from the microphone using PowerShell. Low Platform Analytics Process execution Collection
BIOC Command-line creation of a RAR archive Compression of data into a RAR archive using the rar.exe utility. Informational Platform Analytics Process execution Collection
BIOC Compressed archive created using tar Attackers may use the tar built-in tool to stage a file for exfiltration. Informational Platform Analytics Process execution Collection
Analytics BIOC Compressing data using python Usage of a Python module to compress files. Low Platform Analytics XDR Agent Collection
BIOC Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. Informational Platform Analytics Process execution Collection
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
Analytics BIOC Keylogging using system commands Usage of a Linux system utility to capture input. Low Platform Analytics XDR Agent Credential Access, Collection
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. Medium Platform Analytics XDR Agent Collection
Analytics BIOC Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. Informational Platform Analytics XDR Agent Collection
BIOC PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. Informational Platform Analytics Process execution Collection
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
BIOC Screen capture via command-line tool Attackers may use the window system screen capture tool to collect screenshots. Informational Platform Analytics Process execution Collection
BIOC Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. Informational Platform Analytics File Collection
BIOC Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. Informational Platform Analytics File Collection
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics File Credential Access, Collection
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics Process execution Credential Access, Collection
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. High Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Collection
Analytics BIOC Unusual compressed file password protection An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them. Low Platform Analytics XDR Agent Collection
Analytics BIOC Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection, Reconnaissance
Analytics BIOC Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Collection
BIOC Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. Informational Platform Analytics File Collection
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection