Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Collection |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Correlation Rule | Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. | Medium | Platform Analytics | google_workspace_chrome_raw | Initial Access |
| Analytics BIOC | Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics | Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | New FTP Server A new FTP server has been detected. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Initial Access, Collection |
| BIOC | PsExec runs with System privileges PsExec.exe is a Windows administrative tool, it can be used to elevate privileges and run other processes with NT/System privilege level. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | PsExec was executed with a suspicious command line PsExec.exe was executed. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | The CA policy EditFlags was queried The CA policy EditFlags was queried. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. | Informational | Platform Analytics | Registry | Defense Evasion |