Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

30 detectors match the current filters. technique: T1204 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics BIOC Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. High Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Execution
Correlation Rule Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. Medium Platform Analytics google_workspace_chrome_raw Execution
Analytics BIOC ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Initial Access
Analytics BIOC Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. Low Platform Analytics XDR Agent Execution
Analytics BIOC Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. Low Platform Analytics XDR Agent Execution, Initial Access
BIOC Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns an unsigned process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
Analytics BIOC Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics BIOC Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Persistence
BIOC Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. Informational Platform Analytics File Execution
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
BIOC Process runs with a double extension Look for executables with a common double extension. These are often used to disguise malware as some form of user content. Medium Platform Analytics Process execution Execution
Analytics BIOC Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Low Platform Analytics XDR Agent Execution
BIOC Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by Cymulate Simulation activity performed by Cymulate agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. Informational Platform Analytics File Execution, Resource Development
Analytics BIOC Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). Medium Platform Analytics XDR Agent Execution, Defense Evasion, Privilege Escalation
Analytics BIOC Windows CGO, actor and action processes with anomalous characteristics Windows CGO, actor and action processes with anomalous characteristics. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Windows CGO, actor process and action module with anomalous characteristics Windows CGO, actor process and action module with anomalous characteristics. Informational Platform Analytics XDR Agent Execution