Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

207 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. Informational Platform Analytics File Execution
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Penetration testing tool activity attempt A SaaS API was invoked by a penetration testing tool. Informational Identity Analytics Office 365 Audit Execution
BIOC Perl script connecting to network Perl scripts may be used by attackers to connect to their command-and-control infrastructure. Medium Platform Analytics Process execution Execution
BIOC Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. High Platform Analytics Process execution Execution
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
Analytics Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Credential Access, Execution
Analytics BIOC Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Credential Access
BIOC PowerShell calling Invoke-Expression argument These PowerShell arguments are often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
Analytics BIOC PowerShell Initiates a Network Connection to GitHub PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads. Low Platform Analytics Palo Alto Networks Url Logs Execution
BIOC PowerShell possibly attempting to execute as administrator This PowerShell argument is often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
BIOC PowerShell reverse shell This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell. Medium Platform Analytics Network Execution
BIOC PowerShell running with download in the command line PowerShell can be used to download malicious content from the internet. Informational Platform Analytics Process execution Execution
Analytics BIOC PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. Medium Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. High Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Execution
BIOC Process calls ActiveX Object with a shell command This rule looks for ActiveX being used to run commands on a machine, seen in cases of evasive attacks. Medium Platform Analytics Process execution Execution
BIOC Process runs with a double extension Look for executables with a common double extension. These are often used to disguise malware as some form of user content. Medium Platform Analytics Process execution Execution
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec executed with plain-text credentials on the command line PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands. Informational Platform Analytics Process execution Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
BIOC Psexesvc.exe executes a command from a remote host Psexesvc.exe executes to run a command received from a remote host via PsExec. Informational Platform Analytics Process execution Execution
Analytics BIOC Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
BIOC Python script connecting to network Python scripts may be used by attackers to connect to their command-and-control infrastructure. Medium Platform Analytics Process execution Execution
BIOC Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. Informational Platform Analytics Process execution Discovery, Execution
Analytics BIOC Rare LOLBIN Process Execution by User A user executed a living-off-the-land binary (LOLBIN) process that is unusual for this user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. Informational Platform Analytics XDR Agent Execution
BIOC Remote command executed from a Linux host This tool enables commands to be remotely executed on a Microsoft Windows computer from a Linux computer. This capability is leveraged by attackers to run code remotely, similarly to PsExec. Low Platform Analytics Process execution Execution
Analytics BIOC Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Reverse shell one-liner using a scripting engine An attacker may use scripting engines to execute code from the command line to open a reverse shell. Informational Platform Analytics Process execution Execution
BIOC Reverse shell using PowerShell PowerShell can start a reverse shell console for attackers using these commands and take control of the machine. Informational Platform Analytics Process execution Execution
BIOC Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. High Platform Analytics Process execution Execution
Analytics BIOC Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. Informational Platform Analytics XDR Agent Execution
BIOC Scheduled task created with HTTP or FTP reference Scheduled tasks don't normally include web URLs and may indicate malware activity. Low Platform Analytics Process execution Execution
Analytics BIOC Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics BIOC Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. Informational Platform Analytics XDR Agent Execution
BIOC Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. Informational Platform Analytics Process execution Discovery, Execution
Analytics BIOC Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. Informational Platform Analytics XDR Agent Execution, Persistence
BIOC Simulation activity by AttackIQ Simulation activity performed by AttackIQ agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by Cymulate Simulation activity performed by Cymulate agent. Informational Platform Analytics File Execution, Resource Development
BIOC Simulation activity by SafeBreach Simulation activity performed by a SafeBreach agent. Informational Platform Analytics File Execution, Resource Development
Analytics Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. Low Cortex Cloud AWS Audit Log, Azure Audit Log Execution
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious container runtime connection from within a Kubernetes Pod A process from within a Kubernetes Pod communicated with the container runtime daemon using the runtime socket. This may indicate an adversary attempting to escape from the Kubernetes Pod to the host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious docker image download from an unusual repository The agent has pulled a docker image from a repository for the first time. Informational Platform Analytics XDR Agent Execution
BIOC Suspicious file created in AppData directory A suspicious executable file was created in the AppData directory. Informational Platform Analytics File Execution
Analytics BIOC Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Suspicious process loads a known PowerShell module A non-PowerShell process loaded a known PowerShell module. This image load may be an indication of PowerShell execution without directly invoking the PowerShell.exe binary. Informational Platform Analytics XDR Agent Execution
BIOC Suspicious process loads AMSI DLL Amsi.dll is expected to be loaded from a few known processes (e.g. PowerShell). An image load from an unrelated LOLBIN may indicate PowerShell execution. Informational Platform Analytics Module Execution
Analytics BIOC Suspicious SearchProtocolHost.exe parent process SearchProtocolHost.exe has been launched from a process that is different from SearchIndexer.exe This may indicate malicious activity (such as malware later being injected to it, or it being used for phantom DLL hijacking). Medium Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. Low Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AppleScript designed to access credential files was executed via the command line The AppleScript interpreter was executed with a script designed to access credential files such as keychains or SSH keys. Medium Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. Informational Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. High Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. Informational Cortex Cloud XDR Agent Execution
Analytics BIOC Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). Medium Platform Analytics XDR Agent Execution, Defense Evasion, Privilege Escalation
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon Linux shell command execution An unusual process execution of a shell command on Linux. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon macOS shell command execution An unusual process execution of a shell command on macOS. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon Service Create/Config The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Medium Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unusual AI model invocation A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Unusual AWS CLI/SDK activity A cloud identity invoked an API using AWS CLI/SDK for the first time. Informational Cortex Cloud AWS Audit Log Execution
Analytics BIOC Unusual AWS SageMaker notebook access A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces. Informational Cortex Cloud AWS Audit Log Execution
Analytics BIOC Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Unusual process accessed the PowerShell history file An abnormal process accessed the PowerShell console history file. This may be a sign of malicious PowerShell execution without directly invoking the powershell.exe binary. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. Medium Cortex Cloud XDR Agent Execution
BIOC Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Process execution Execution
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
BIOC VBScript execution from the command line Attackers may run VBScript code from the command line using signed processes such as Mshta. Informational Platform Analytics Process execution Execution