Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
29 detectors match the current filters. tactic: TA0040 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Impact |
| Analytics BIOC | A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Broker Collection Error A collection error was detected on a broker VM. | Informational | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Collection error A collection error was detected. | High | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Correlation rule error An error was identified while running a correlation rule. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| Correlation Rule | DropBox - Massive File Alterations This rule detects more than 100 edited files during an hour by the same user. This is a suspicious behavior which can be an indication of a ransomware attack. | High | Platform Analytics | dropbox_dropbox_raw | Impact |
| Analytics BIOC | Error in event forwarding An error was detected in event forwarding. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Internet Explorer home page modification The Internet Explorer home page could be changed to a malicious page. | Low | Platform Analytics | Registry | Impact, Credential Access |
| Analytics | Logs were not collected from a data source for an abnormally long time Logs were not collected from a data source for an abnormally long time. | Low | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Manipulation of permissions for the Application Event Log Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx. | Informational | Platform Analytics | Registry | Impact |
| BIOC | Manipulation of Volume Shadow Copy configuration Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy. | Informational | Platform Analytics | Registry | Impact |
| BIOC | Manipulation of Windows Safe Boot configuration Safe-boot Registry settings deletion. | Medium | Platform Analytics | Registry | Impact |
| BIOC | Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| Analytics BIOC | Parsing Rule Error A Parsing Rule error was detected. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Possible data destruction via dd Attackers may use dd to zero out or write random data to files. | Informational | Platform Analytics | Process execution | Impact |
| BIOC | Process changes the Windows logon text This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user. | Medium | Platform Analytics | Registry | Impact |
| BIOC | Process requests the deletion of Windows Shadowcopies Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism). | High | Platform Analytics | Process execution | Impact |
| BIOC | Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. | Informational | Platform Analytics | Process execution | Impact |
| Analytics | Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Impact |
| Analytics BIOC | Suspicious data encryption Known applications were used to encrypt data within a machine's local file system. | Low | Platform Analytics | XDR Agent | Impact, Defense Evasion |
| Analytics | Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. | Low | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. | Informational | Platform Analytics | XDR Agent | Impact |
| BIOC | Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. | Low | Platform Analytics | Registry | Defense Evasion, Impact |
| Analytics BIOC | Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. | Informational | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. | High | Platform Analytics | XDR Agent | Impact |
| Analytics BIOC | Windows Event Log was cleared using wevtutil.exe A command-line utility was used to clear the Windows Event Log. It may be used to delete logs to cover the tracks of the malicious activity, making it harder to perform analysis. | Low | Platform Analytics | XDR Agent | Impact |
| BIOC | Windows File Protection being disabled via Registry Windows File Protection (WFP) prevents programs from replacing critical Windows system files. Programs must not overwrite these files because they are used by the operating system and by other programs. Protecting these files prevents problems with programs and the operating system. | Low | Platform Analytics | Registry | Impact |
| BIOC | WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. | Informational | Platform Analytics | Process execution | Credential Access, Impact |