Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. technique: T1074 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. Informational Platform Analytics Process execution Collection
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. Informational Platform Analytics File Collection
BIOC Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. Informational Platform Analytics Process execution Collection