Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

21 detectors match the current filters. technique: T1036 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics BIOC A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Common Apple process name missing Apple digital signature These common Apple process names should normally be signed with the Apple Inc. digital signature. Naming processes with common names is a common way attackers obfuscate their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Common Mozilla process name missing Mozilla digital certificate These common Mozilla process names should normally be signed with the Mozilla Corporation digital signature. Naming processes with common names is a common way attackers obfuscate their activities. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. Informational Platform Analytics XDR Agent Defense Evasion
BIOC File renamed to have a script extension Adversaries may create 'benign-looking' files, which are later used as malicious scripts by changing their extension. Informational Platform Analytics File Defense Evasion
Analytics BIOC Masquerading as the Linux crond process Copies a file and renames it as crond. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
BIOC Shell binary copied to another location Attackers may try to evade detection by copying the shell binary to an innocent-looking name. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. Informational Platform Analytics File Defense Evasion
BIOC Suspicious .NET process spawns csc.exe A suspicious process in the Microsoft .NET directory spawned the C# compiler. This may occur if an attacker masquerades a process like MSBuild (e.g. PowerLessShell). Low Platform Analytics Process execution Defense Evasion
Analytics BIOC Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. Informational Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious Process Spawned by wininit.exe An unusual process was spawned by wininit.exe, possibly indicating malicious local or remote code execution. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Svchost.exe loads a rare unsigned module Svchost.exe loads a rare unsigned module, which can indicate an attacker's malicious service execution. Low Platform Analytics XDR Agent Defense Evasion, Persistence
BIOC Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. Informational Platform Analytics Process execution Defense Evasion