Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1677 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Pluggable Authentication Modules Access Access to Pluggable Authentication Modules. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Pluggable Authentication Modules Modification Modification of Pluggable Authentication Modules. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Port Monitor added in Registry Adversaries may use port monitors to run an adversary-supplied DLL during system boot for persistence or privilege escalation. | Low | Platform Analytics | Registry | Persistence |
| Analytics | Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls | Discovery |
| Analytics | Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| BIOC | Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible binary padding using dd A suspicious dd command ran and added data to a binary. This may indicate binary padding to change the hash of a file. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics | Possible Brute Force in universal authentication An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack. | Informational | Identity Analytics | Credential Access, Resource Development | |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| BIOC | Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. | Medium | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| BIOC | Possible data destruction via dd Attackers may use dd to zero out or write random data to files. | Informational | Platform Analytics | Process execution | Impact |
| Analytics | Possible data exfiltration over a USB storage device A process generated massive file creation, renaming and write activity to a USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Possible data obfuscation A command that can be used for file obfuscation was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Possible DLL Search Order Hijacking An attacker might abuse the Windows DLL search order to trigger known, signed processes to load the attacker's malicious module. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. | Informational | Platform Analytics | XDR Agent | Collection |
| Analytics | Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| BIOC | Possible Firefox browser history and bookmarks collection via command-line tool Attackers may collect history and bookmarks details by accessing the Firefox database. | Medium | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible GPO Enumeration A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Resource Development |
| Analytics | Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics | Possible internal data exfiltration over a USB storage device A user generated abnormal massive file activity to a connected USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics | Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible Kerberoasting without SPNs A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics BIOC | Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. | Low | Platform Analytics | Windows Event Collector, XDR Agent | Privilege Escalation |
| Analytics | Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Possible log destruction using the dd command Possible destruction of system log files using the dd command. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | High | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Possible malicious .NET compilation started by a commonly abused process Attackers may use csc.exe to compile payloads on a compromised machine. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics | Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. | Low | Identity Threat Detection (ITDR) | Office 365 Audit | Initial Access |
| Analytics BIOC | Possible network service discovery via command-line tool An attacker may use command-line utilities to discover open ports and services on a remote host. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. | Medium | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Possible Oracle enumeration via Oscanner The Oscanner Oracle framework performs enumeration of SIDs, account roles, privileges, hashes, and more. Attackers may attempt to gather this information during the reconnaissance phase. | Low | Platform Analytics | Process execution | Discovery |
| BIOC | Possible Oracle enumeration via tnscmd10g The tnscmd10g command-line utility was executed, allowing the enumeration of Oracle DBs. | Low | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible Pass-the-Hash An account was successfully logged on to with new credentials. This login type is rare and may be an attacker's attempt to pass-the-hash and move laterally within a network. | Low | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics | Possible Password Spray in universal authentication An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack. | Informational | Identity Analytics | Credential Access, Resource Development | |
| Analytics BIOC | Possible path traversal via HTTP request The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Discovery |
| Analytics BIOC | Possible Persistence via group policy Registry keys Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| BIOC | Possible ping sweep Ping sweeps are useful tools that can detect which machines are up in the network and can be the step before lateral movement. | Medium | Platform Analytics | Process execution | Discovery |
| Analytics | Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Possible RDP session hijacking using tscon.exe The executable tscon.exe can be used to hijack other sessions on the same computer. The attacker may use another user's credentials to proceed with the lateral movement or disguise the activity. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Possible Search For Password Files Attackers often search for files that have passwords in them. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Possible TGT reuse from different hosts (pass the ticket) We observed two different hosts sending TGS using the same TGT. This may indicate a TGT was stolen and passed to another host. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| BIOC | Possible UAC bypass via Event Viewer Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| BIOC | Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible web shell command execution Possible command execution via a web shell for reconnaissance. | Informational | Platform Analytics | Process execution | Persistence |
| Analytics BIOC | Possible webshell file written by a web server process An uncommon file with a web file extension was created, written or renamed by a web server process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| BIOC | Possible XDG autostart persistency Possible persistency gained by writing or creating a desktop file inside the xdg autostart directory. | Informational | Platform Analytics | File | Persistence |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics | Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |
| Analytics | Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics BIOC | Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Collection, Initial Access |
| Analytics | Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. | Medium | Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log | Initial Access |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| Analytics BIOC | Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion |
| BIOC | Potential web shell installation A web-app script file was installed on a web server. This can indicate an installation of web shell. | Informational | Platform Analytics | File | Persistence |
| BIOC | PowerShell calling Invoke-Expression argument These PowerShell arguments are often used to run commands with malicious intent. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | PowerShell creates a new service PowerShell creates a new service via a command line. This can be used by attackers to be persistent on a machine. | Low | Platform Analytics | Process execution | Persistence |
| BIOC | PowerShell downloads files via BITS This PowerShell argument is often used to run commands with malicious intent. | Medium | Platform Analytics | Process execution | Persistence |
| BIOC | PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). | Medium | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | PowerShell Initiates a Network Connection to GitHub PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads. | Low | Platform Analytics | Palo Alto Networks Url Logs | Execution |
| BIOC | PowerShell is used to execute a CPL file Attackers may use PowerShell.exe to execute a CPL file to achieve Control Panel proxy execution. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | PowerShell possibly attempting to execute as administrator This PowerShell argument is often used to run commands with malicious intent. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | PowerShell reverse shell This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell. | Medium | Platform Analytics | Network | Execution |
| BIOC | PowerShell running with download in the command line PowerShell can be used to download malicious content from the internet. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. | Low | Platform Analytics | XDR Agent | Execution |
| BIOC | PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. | Medium | Platform Analytics | Process execution | Credential Access |
| BIOC | PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. | Medium | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. | Medium | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. | High | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| BIOC | Print Processor Registration Adversaries may abuse print processors to run malicious DLLs during system boot that will be executed as SYSTEM for privilege escalation and/or persistence. | Low | Platform Analytics | Registry | Persistence |