Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
18 detectors match the current filters. technique: T1070 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Accessing bash history file Clearing bash history file is a known procedure of attackers to delete traces. | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Accessing bash history file using bash commands Clearing bash history files is a known attacker procedure for covering their tracks. | Low | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Clear logs - using dd and /dev/null Usage of the dd utility to clear the contents of a file using /dev/null. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Clearing logs by copying /dev/null to a log file Usage of the cp command to copy /dev/null to a file and clear its content. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Clearing logs by executing cat /dev/null Usage of cat /dev/null to clear the contents of a log file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| Analytics BIOC | Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Delete Volume USN Journal with fsutil This technique is used by attackers to eliminate evidence of files created during post-exploitation activities. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Log deletion in known log file directories Deletion of log files in known log directories. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | Log deletion using the truncate command Usage of the truncate utility using "-s 0" argument to clear log files. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Log deletion via command-line tool An attacker may use the rm command to remove traces of their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Possible log destruction using the dd command Possible destruction of system log files using the dd command. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Uncommon attempt to clear shell history An attempt to clear or manipulate shell history files was detected. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Windows event logs cleared using wmic.exe Attackers may clear events from Windows event logs to remove traces of their malicious activity. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. | Informational | Platform Analytics | Windows event log | Defense Evasion |