Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1677 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple Okta MFA requests sent to a user Multiple SSO MFA attempts were sent to the user. This may indicate an MFA fatigue attack. Informational Identity Analytics Okta Credential Access, Resource Development
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
BIOC Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. Medium Platform Analytics Registry Persistence, Lateral Movement
Analytics Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics Multiple suspicious user accounts were created A user was observed creating multiple rare user accounts. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Multiple uncommon SSH Servers with the same Server host key Multiple uncommon SSH servers were observed using the same host key. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access
Analytics Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics XDR Agent Credential Access
Analytics Multiple user accounts were deleted A user deleted multiple user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Impact
Analytics Multiple users authenticated with weak NTLM to a host Multiple user accounts authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be a result of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
BIOC Nagios enumeration A Nagios XI database may be enumerated for the credentials of the hosts monitored. Low Platform Analytics Process execution Credential Access
Analytics BIOC Near-empty email from an external sender The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context. Informational Email Security Microsoft 365 Emails Reconnaissance
Analytics BIOC Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. High Platform Analytics XDR Agent Command and Control
BIOC Netcat shell via named pipe Attackers may create a Netcat shell using a named pipe to remotely access the endpoint. Informational Platform Analytics Process execution Execution
BIOC Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. Informational Platform Analytics Process execution Credential Access
BIOC Netsh.exe modifies allowed firewall port/program lists Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use. Informational Platform Analytics Process execution Defense Evasion
BIOC Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. Informational Platform Analytics Process execution Discovery
BIOC Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. Informational Platform Analytics Process execution Discovery
BIOC Network share discovery via command-line tool Attackers may use command-line tools to discover mapped shares on the host. Low Platform Analytics Process execution Discovery
Analytics BIOC Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access, Discovery
Analytics BIOC New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. Low Platform Analytics XDR Agent Defense Evasion
Analytics New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
BIOC New certificate added to the trusted root store Untrusted certificates could be used to install untrusted drivers and malicious code. Informational Platform Analytics Process execution Defense Evasion
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
BIOC New entry added to startup related Registry keys by unsigned process Entries added to the "Run Keys" in the Registry or the startup folder will cause the program to be executed when the user logs in. The program will be executed in the context of the user and will have his permissions level. Informational Platform Analytics Registry Persistence
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
BIOC New local user created via PowerShell command line Attackers may create new local users to persist access to machines. Medium Platform Analytics Process execution Persistence
BIOC New service created via command line Attackers may leverage services to gain persistence on an endpoint. Informational Platform Analytics Process execution Persistence
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC New Teams application published to the organization catalog A new Teams application was published to the organization catalog. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Non-browser access to a pastebin-like site Non-browser access to a pastebin-like site. Low Platform Analytics Palo Alto Networks Url Logs Command and Control
BIOC Non-browser process downloads content from GitHub Check for possible attempts to use GitHub as a malicious payload deployment mechanism. This technique is known to be used frequently by threat actors to serve malicious scripts/payloads. Informational Platform Analytics Network Command and Control
BIOC Notepad process makes a network connection Notepad.exe processes should not normally make network connections (with the occasional exception of printing documents). This can be a possible indicator of exploitation, e.g. Metasploit Meterpreter injection. Low Platform Analytics Network Defense Evasion
Analytics BIOC NTDS.dit file written by an uncommon executable The Active Directory database file was written by an uncommon process to a non-default location. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics File Credential Access
Analytics NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
BIOC NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. Medium Platform Analytics Process execution Credential Access
Analytics NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics Numerous emails sent by a single sender to multiple internal recipients Numerous emails were sent to multiple internal recipients. This may indicate spam or any other malicious attempt. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Object versioning was disabled Object versioning of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Impact
BIOC Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. Informational Platform Analytics Process execution Initial Access
Analytics BIOC Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Persistence
Analytics BIOC Office process spawned with suspicious command-line arguments An Office process was executed with LOLBIN-like command-line arguments. This behavior is exhibited in the VBA-RunPE tool that executes executables from the memory of Word/Excel/PowerPoint. Low Platform Analytics XDR Agent Defense Evasion
BIOC Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. Informational Platform Analytics Process execution Initial Access
BIOC Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. Informational Platform Analytics File Execution
Analytics Okta account reset password attempt A user used a weak factor to reset their Okta password. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics Okta account unlock Okta user account was unlocked. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta account unlock by admin An administrative user unlocked an Okta account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta admin privilege assignment A user assigned admin privileges to a new user or group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics Okta device assignment A device was assigned as an Okta MFA device to a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics BIOC Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics Okta Reported Threat Detected Okta Threat Insight Reported Threat Detected. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta User Session Impersonation A user has initiated a session impersonation in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC OneDrive file download A file was downloaded from OneDrive using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics BIOC OneDrive file upload A file was uploaded to OneDrive using Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Resource Development
Analytics BIOC OneDrive folder creation A folder was created in OneDrive using Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
BIOC Out of band testing domain connection Connection from web service process to out-of-band-testing domain. Low Platform Analytics Network Initial Access
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
BIOC Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. Informational Platform Analytics File Initial Access
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Owner added to Azure application An identity was added as an owner to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
Analytics BIOC Parsing Rule Error A Parsing Rule error was detected. Medium Platform Analytics Health Monitoring Data Impact
BIOC Password complexity enumeration Attackers may read system files containing password complexity requirements. Informational Platform Analytics Process execution Discovery
BIOC Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. Informational Platform Analytics Process execution Discovery
BIOC Password-related Mozilla files were read by a non-Mozilla process Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Informational Platform Analytics File Credential Access
Analytics BIOC Penetration testing tool activity attempt A SaaS API was invoked by a penetration testing tool. Informational Identity Analytics Office 365 Audit Execution
BIOC Perl script connecting to network Perl scripts may be used by attackers to connect to their command-and-control infrastructure. Medium Platform Analytics Process execution Execution
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
BIOC Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. Informational Platform Analytics Process execution Discovery
BIOC Permissive file privileges were granted Setting readable, writable, and executable permissions for all users may pose a major security risk. Informational Platform Analytics Process execution Defense Evasion
BIOC Persistence through service registration An attacker may add or modify system services to persist on a host. Informational Platform Analytics File Persistence
BIOC Persistence using bashrc files Possible persistency using shell (bash\csh) profile files. Commands in ~/.bashrc are executed on every new shell execution. Informational Platform Analytics File Persistence
BIOC Persistence using cron jobs Cron jobs are tasks to be executed sometime in the future, and could be used to persist malware. Informational Platform Analytics File Persistence
BIOC Persistence via Registry screensaver key change Attackers may install their malware persistently by modifying the value of the screensaver Registry key. Informational Platform Analytics Registry Persistence
Analytics BIOC Phantom DLL Loading An attacker might leverage existing processes missing module loads to load malicious code into trusted processes. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. Informational Cortex Cloud Azure Audit Log Impact
BIOC Ping executed with loopback address This seemingly strange "wait" mechanism is often used by malware to stall command execution. Informational Platform Analytics Process execution Defense Evasion
BIOC Ping to a known external IP address Pinging a known external IP address is often used by malware to check internet connectivity. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Ping to localhost from an uncommon, unsigned parent process Ping is often used by malware and attackers to delay the execution of suspicious commands in sandbox environments. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Privilege Escalation
BIOC Plink/SSH reverse tunnel PuTTY link (Plink) / SSH can be used to create encrypted tunnels to communicate back to an attacker's C2 server. Low Platform Analytics Process execution Command and Control