Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. technique: T1014 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Driver written to a temporary directory Drivers are highly unlikely to be written or moved to a temp directory. Check whether this driver is legitimate. Informational Platform Analytics File Defense Evasion
BIOC Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. Informational Platform Analytics Process execution Defense Evasion, Impact
BIOC Tampering with the Windows System Restore configuration System Restore was disabled on the endpoint. In such a case, one may not be able to recover files in case of disaster. This may be initiated by the IT department, but also may indicate malicious activity such as ransomware. Low Platform Analytics Registry Defense Evasion, Impact
Analytics BIOC Uncommon driver loaded An uncommon driver loaded which may be an attempt to kill the EDR or install rootkit. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon kernel module load Loading of a kernel module using the modprobe command. Informational Platform Analytics XDR Agent Defense Evasion