Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1677 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon VNC server communication Uncommon VNC server network traffic was observed. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics | Uncommon WPAD queries There were multiple attempts to access WPAD resources by a single host in your network. This may indicate a malicious activity. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics BIOC | Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. | High | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unpopular rsync process execution An unpopular rsync process was executed on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Unrecognized internal address (AAD mismatch) An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| BIOC | Unsigned integer Sudo privilege escalation Fixed in CVE-2019-14287, this known command line is used to exploit a bug in sudo to gain root privileges. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. | Informational | Platform Analytics | File | Credential Access |
| Analytics BIOC | Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| BIOC | Unsigned process creates an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. Malware may attempt to evade discovery by placing their payload in an ADS. | Informational | Platform Analytics | File | Defense Evasion |
| Analytics BIOC | Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Privilege Escalation |
| BIOC | Unsigned process injects code into a process An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack. | Informational | Platform Analytics | Remote code | Defense Evasion |
| BIOC | Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| BIOC | Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process running from a temporary directory Malware often runs from a temporary folder. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Untrusted process contacted LLM API An untrusted process contacted an LLM API. | Informational | Platform Analytics | XDR Agent | Resource Development |
| Analytics BIOC | Unusual access to Microsoft 365 storage services Unusual access was detected to a Microsoft 365 storage service. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual access to the Windows Internal Database on an ADFS server The Windows Internal Database (WID) was queried in an unusual way on an ADFS server. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual ADConnect database file access An unusual process accessed the ADConnect database files. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Lateral Movement |
| Analytics BIOC | Unusual AI dataset modification A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Unusual AI Knowledge Base Modification An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Unusual AI model invocation A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | Unusual AI RAG Knowledge Base Modification AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact |
| Analytics | Unusual attachment volume in outbound emails Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| Analytics BIOC | Unusual AWS Bedrock model access request A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | Unusual AWS CLI/SDK activity A cloud identity invoked an API using AWS CLI/SDK for the first time. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics | Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Unusual AWS SageMaker notebook access A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Lateral Movement |
| Analytics BIOC | Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual Azure AD sync module load A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module. | Low | Identity Threat Detection (ITDR) | XDR Agent | Credential Access |
| Analytics BIOC | Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual CertLog Remote File Write A remote host wrote to a certificate log file via RPC over SMB, which may indicate the use of an AD CS attack tool like Certipy. This behavior is commonly associated with certificate-based authentication attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |
| Analytics BIOC | Unusual compressed file password protection An adversary might compress sensitive files with password protection to bypass security mitigations when attempting to exfiltrate them. | Low | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Unusual Conditional Access operation for an identity An identity attempted to add or update an Azure AD Conditional Access policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Unusual cross projects activity A suspicious activity between different cloud projects. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. | Informational | Platform Analytics | XDR Agent | Initial Access, Lateral Movement |
| Analytics BIOC | Unusual display name in From header An email was detected with an unusual display name in the From header. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Unusual Encrypting File System Remote call (EFSRPC) to domain controller An unusual Encrypting File System Remote call (EFSRPC) was made to a domain controller. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unusual hostname for the sending mail server in the email headers The detected mail server hostname had not been observed in the organization's emails in the past 30 days. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Unusual IAM enumeration activity by a non-user Identity An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity. | Informational | Cortex Cloud | Gcp Audit Log | Discovery |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Discovery |
| Analytics BIOC | Unusual key management activity A cloud identity performed a key management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Unusual Kubernetes secret access Suspicious Kubernetes secret access. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual Lolbins Process Spawned by InstallUtil.exe An unusual process was spawned by InstallUtil.exe, possibly indicating malicious local or remote code execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics | Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| Analytics BIOC | Unusual process access to ld.so.preload file Attackers can modify ld.so.preload to inject malicious code into every dynamically linked process, enabling persistence and code execution. This detected operation is considered atypical in terms of access. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Reconnaissance |
| Analytics BIOC | Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Collection |
| Analytics BIOC | Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Unusual process accessed web browser cookies An unusual process has accessed a web browser's session cookie store. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process accessed web browser credentials An unusual process has accessed a web browser credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. | Medium | Cortex Cloud | XDR Agent | Execution |
| BIOC | Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. | Informational | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Unusual resource access by Azure application An Azure application had interacted with an unusual resource using the Microsoft Graph API. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Privilege Escalation, Impact |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual sender IP subnet This IP address has not been observed in correlation with the sender's fully qualified domain name within the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics | Unusual SSH Activity Unusual SSH activity was detected that involved a higher than usual volume of data transfer and an abnormally long session. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control |
| Analytics BIOC | Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control |
| Analytics BIOC | Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Unusual use of a 'SysInternals' tool An attacker may be trying to avoid detection by using an obfuscated copy of SysInternals tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. | Informational | Identity Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Unverified domain added to Azure AD A new unverified domain was added to Azure AD. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| BIOC | Usage of tracing tool An attacker may be trying to use a known tracing tool to gather information from other processes. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics | User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Collection |