Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
114 detectors match the current filters. technique: T1562 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | The Linux system firewall was disabled The system firewall was disabled. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |
| Analytics BIOC | User set insecure CA registry setting for global SANs A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows set to permit unsigned drivers (Test Mode) This host has been set into 'Test Mode' which allows loading of unsigned drivers. It has legitimate uses, but can be leveraged by malware to load malicious untrusted drivers. | Medium | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. | Informational | Platform Analytics | Process execution | Defense Evasion, Execution |