Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
19 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics BIOC | Execution of dllhost.exe with an empty command line The process dllhost.exe was executed with an empty command line. This behavior is suspicious, and may be caused by a malicious actor using 'Image File Execution Options' in the registry to evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | LOLBIN created a PSScriptPolicyTest PowerShell script file A LOLBIN created a PSScriptPolicyTest file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Mshta.exe launched with suspicious arguments Microsoft HTML application host process has been launched with suspicious arguments, which may indicate malicious intent. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Mshta.exe spawns from a browser process Mshta is the Microsoft HTML Application Host. It executes HTML applications on Windows. Detected when a browser process has spawned mshta, which can be a potential attack vector. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | MSI accessed a web page running a server-side script The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Msiexec execution of an executable from an uncommon remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious certutil command line An attacker may use certutil to download malware. | Medium | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Uncommon msiexec execution of an arbitrary file from a remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| Analytics BIOC | Wscript/Cscript loads .NET DLLs An unusual script loads .NET DLLs, possibly indicating JScriptToDotnet execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |