Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1677 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Removal of an Azure Owner from an Application or Service Principal An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Retrieval of cloud compute EC2 instance user data A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. Informational Cortex Cloud AWS Audit Log Collection
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
BIOC Reverse shell one-liner using a scripting engine An attacker may use scripting engines to execute code from the command line to open a reverse shell. Informational Platform Analytics Process execution Execution
BIOC Reverse shell using PowerShell PowerShell can start a reverse shell console for attackers using these commands and take control of the machine. Informational Platform Analytics Process execution Execution
BIOC Root certificate installed Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Informational Platform Analytics Registry Defense Evasion
BIOC Root certificate installed Installation of a root certificate on a compromised system would give an adversary a way to degrade the security of that system. Informational Platform Analytics Process execution Defense Evasion
BIOC Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. High Platform Analytics Process execution Execution
Analytics BIOC Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. Informational Platform Analytics XDR Agent Execution
BIOC Rundll32 loads a known abused DLL Rundll32.exe is called to execute an arbitrary binary, this execution may also bypass whitelisting defenses as a signed Microsoft application. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. Low Platform Analytics XDR Agent Defense Evasion
BIOC Rundll32.exe launches an executable using ordinal numbers argument Rundll32.exe launches an executable using ordinal numbers argument, this behavior may be used by attackers to evade detection. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. Medium Platform Analytics XDR Agent Defense Evasion
BIOC Rundll32.exe was used to run JavaScript Attackers may execute malicious JavaScript code (either remotely or locally) using rundll32.exe. Medium Platform Analytics Process execution Defense Evasion
BIOC Rundll32.exe with 'main' as EntryPoint Rundll32.exe ran with 'main' as EntryPoint. Attackers may leverage rundll32.exe to execute malicious functions and DLLs. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. Informational Email Security Office 365 Audit Collection
Analytics BIOC SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Initial Access
Analytics SCCM log files enumeration Multiple local SCCM logs were accessed within a short period of time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Scheduled task created with HTTP or FTP reference Scheduled tasks don't normally include web URLs and may indicate malware activity. Low Platform Analytics Process execution Execution
Analytics BIOC Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. Informational Platform Analytics XDR Agent Execution, Persistence
BIOC Screen capture via command-line tool Attackers may use the window system screen capture tool to collect screenshots. Informational Platform Analytics Process execution Collection
Analytics BIOC Screensaver process executed from Users or temporary folder An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Script file added to startup-related Registry keys An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
BIOC Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. Informational Platform Analytics File Collection
BIOC Scripting engine creates an Alternate Data Stream (ADS) Malware may hide data inside alternate data streams instead of inside a file. Informational Platform Analytics File Defense Evasion
BIOC Scripting engine makes connections over DNS ports Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. Informational Platform Analytics Network Exfiltration
BIOC Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. Informational Platform Analytics File Collection
Analytics BIOC SecureBoot was disabled SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
BIOC Security services stopped Attackers may stop security critical services to avoid possible detection of their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. Informational Platform Analytics Registry Privilege Escalation
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
BIOC SELinux was set to permissive mode SELinux was set to permissive mode using the "setenforce 0" command. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Sending unusual file(s) to an external address Unusual files sent to an external address. Low Email Security Microsoft 365 Emails Initial Access, Exfiltration
Analytics BIOC Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics BIOC Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC SES Production Access Requested An identity requested to move the SES account from a restricted sandbox mode into production mode. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. Low Platform Analytics XDR Agent Privilege Escalation, Defense Evasion
BIOC Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. Informational Platform Analytics Process execution Privilege Escalation
BIOC Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. Informational Platform Analytics Process execution Discovery, Execution
Analytics BIOC SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
BIOC SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. Medium Platform Analytics Windows event log Discovery
BIOC Shell binary copied to another location Attackers may try to evade detection by copying the shell binary to an innocent-looking name. Informational Platform Analytics Process execution Defense Evasion
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics File Credential Access, Collection
BIOC Shell history access Attackers may search historical commands for credentials and information gathering. Informational Platform Analytics Process execution Credential Access
BIOC Shell History Access Access to files holding shell history information. Informational Platform Analytics Process execution Credential Access, Collection
BIOC Shim database file access An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence. Informational Platform Analytics File Persistence, Privilege Escalation
BIOC Shim database registration via Registry Application shim databases may be leveraged for privilege escalation and persistence, and can be installed by modifying the Registry. Informational Platform Analytics Registry Persistence
Analytics Short-lived Azure AD user account An Azure AD user was created and deleted within a short period of time. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics Short-lived user account A user was created and deleted within a short period of time. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. Informational Platform Analytics Process execution Impact
Analytics BIOC Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by Cymulate Simulation activity performed by Cymulate agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. Informational Platform Analytics File Execution, Resource Development
Analytics Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC SmartScreen disabled via Registry These Registry keys control the SmartScreen. Malware may turn it off to evade SmartScreen functionality. Informational Platform Analytics Registry Defense Evasion
BIOC SMB enumeration via command-line tool Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources. Informational Platform Analytics Process execution Discovery
Analytics BIOC SMB Traffic from Non-Standard Process SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. Low Platform Analytics XDR Agent Discovery
BIOC Socat/Netcat connects to TOR domain Unlikely behavior in standard systems. Medium Platform Analytics Network Command and Control
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. Informational Platform Analytics File Defense Evasion
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics BIOC SPNs cleared from a machine account Service principal names were cleared from a machine account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. Informational Identity Analytics XDR Agent Credential Access
BIOC SSH key pair discovery Attackers may look for SSH key pairs using the find command. Informational Platform Analytics Process execution Credential Access
Analytics BIOC SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a machine account A machine account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a service account A service account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics SSO Brute Force An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics SSO Password Spray An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. Informational Identity Analytics AzureAD, Okta, OneLogin Initial Access
Analytics BIOC SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. Informational Identity Analytics Okta, AzureAD, Azure SignIn Log, Duo, PingOne Initial Access
Analytics BIOC SSO with new operating system A user successfully authenticated via SSO with a new operating system. Informational Identity Analytics Okta, Azure SignIn Log, AzureAD, Duo Initial Access
Analytics Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. Low Platform Analytics XDR Agent Credential Access
Analytics Subdomain Fuzzing The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics BIOC Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. Informational Identity Analytics Initial Access
Analytics BIOC Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. Medium Platform Analytics XDR Agent Privilege Escalation
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
Analytics BIOC SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. Low Platform Analytics XDR Agent Discovery
BIOC SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. High Platform Analytics Module Initial Access, Command and Control
Analytics BIOC Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). Medium Platform Analytics XDR Agent Defense Evasion
BIOC Suspicious .NET process spawns csc.exe A suspicious process in the Microsoft .NET directory spawned the C# compiler. This may occur if an attacker masquerades a process like MSBuild (e.g. PowerLessShell). Low Platform Analytics Process execution Defense Evasion
Analytics BIOC Suspicious access of the System Management Container A user accessed the System Management container, which may be an indication of a reconnaissance for site servers. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
BIOC Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. Informational Platform Analytics File Discovery