Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. technique: T1074 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| BIOC | PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| BIOC | Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. | Informational | Platform Analytics | File | Collection |
| BIOC | Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |