Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

255 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. Informational Platform Analytics File Defense Evasion
BIOC SSH key pair discovery Attackers may look for SSH key pairs using the find command. Informational Platform Analytics Process execution Credential Access
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
BIOC Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. Informational Platform Analytics File Discovery
BIOC Suspicious file created in AppData directory A suspicious executable file was created in the AppData directory. Informational Platform Analytics File Execution
BIOC Suspicious process loads AMSI DLL Amsi.dll is expected to be loaded from a few known processes (e.g. PowerShell). An image load from an unrelated LOLBIN may indicate PowerShell execution. Informational Platform Analytics Module Execution
BIOC Suspicious SDB file written to disk Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files may be indicative of this technique. Informational Platform Analytics File Persistence
BIOC Suspicious SDB file written to disk by an unsigned process Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files by an unsigned process may be indicative of this technique. Informational Platform Analytics File Persistence
BIOC Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. Informational Platform Analytics Process execution Defense Evasion
BIOC SyncAppvPublishingServer used to run PowerShell code SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code. Informational Platform Analytics Process execution Defense Evasion
BIOC System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. Informational Platform Analytics Process execution Discovery
BIOC System network configuration discovery System network configuration discovery using Linux command-line utilities. Informational Platform Analytics Process execution Discovery
BIOC System owner/user discovery System owner/user discovery using bash utilities. Informational Platform Analytics Process execution Discovery
BIOC Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. Informational Platform Analytics Registry Defense Evasion
BIOC Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. Informational Platform Analytics Registry Defense Evasion
BIOC Tampering with Windows Security Support Provider DLLs Windows Security Support Provider (SSP) DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored on Windows, such as any logged-on user's Domain password etc. CurrentControlSet is replaced with * because it can be replaced with ControlSet001 or ControlSet002. Informational Platform Analytics Registry Persistence
BIOC Task scheduled by commonly abused host process Attackers will often attempt to abuse shell/host processes to create a persistent payload in the form of a scheduled task. Check for malicious use. Informational Platform Analytics Process execution Persistence
BIOC The scripting engine executed code from an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. An attacker may try to evade detection by executing malware from the ADS value of a file. Informational Platform Analytics Process execution Defense Evasion
BIOC Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. Informational Platform Analytics File Credential Access
BIOC Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. Informational Platform Analytics File Credential Access
BIOC Unsigned process creates an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. Malware may attempt to evade discovery by placing their payload in an ADS. Informational Platform Analytics File Defense Evasion
BIOC Unsigned process injects code into a process An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack. Informational Platform Analytics Remote code Defense Evasion
BIOC Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. Informational Platform Analytics Network Exfiltration
BIOC Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Informational Platform Analytics File Credential Access
BIOC Unsigned process running from a temporary directory Malware often runs from a temporary folder. Informational Platform Analytics Process execution Defense Evasion
BIOC Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. Informational Platform Analytics Process execution Privilege Escalation
BIOC Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Process execution Execution
BIOC Usage of tracing tool An attacker may be trying to use a known tracing tool to gather information from other processes. Informational Platform Analytics Process execution Defense Evasion
BIOC User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. Informational Platform Analytics Registry Defense Evasion
BIOC User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. Informational Platform Analytics File Persistence
BIOC VBScript execution from the command line Attackers may run VBScript code from the command line using signed processes such as Mshta. Informational Platform Analytics Process execution Execution
BIOC VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. Informational Platform Analytics Process execution Discovery
BIOC VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. Informational Platform Analytics Process execution Discovery
BIOC Web browser cookie and credential access Detect attempt to acquire cookies or credentials from a Safari browser. Informational Platform Analytics Process execution Credential Access
BIOC Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. Informational Platform Analytics File Initial Access
BIOC Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. Informational Platform Analytics Process execution Initial Access
BIOC Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. Informational Platform Analytics Network Exfiltration
BIOC Windows 10 Developer Mode enabled Enabling developer mode allows for app sideloading and starts the Windows SSH services, which may be used to install Linux Bash on Windows. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. Informational Platform Analytics Registry Defense Evasion
BIOC Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. Informational Platform Analytics File Collection
BIOC Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. Informational Platform Analytics Registry Defense Evasion
BIOC Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. Informational Platform Analytics Process execution Defense Evasion
BIOC Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. Informational Platform Analytics Windows event log Defense Evasion
BIOC Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. Informational Platform Analytics Registry Defense Evasion
BIOC WinPmem Forensics Tool The WinPmem Forensics Tool has been run. Informational Platform Analytics Process execution Collection, Credential Access
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact
BIOC WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. Informational Platform Analytics Process execution Defense Evasion, Execution
BIOC Write to .bash_profile Commands in ~/.bash_profile are executed on every user shell login with a username and password. Informational Platform Analytics File Persistence
BIOC Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. Informational Platform Analytics File Discovery
BIOC Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Wscript.exe connects to an external network It may be due to local IT or administrative tools used on endpoints, but it could also indicate exfiltration of data between hosts in the local network, malware droppers, beaconing and so on. The execution chain should be reviewed to determine the context of the activity. Informational Platform Analytics Network Execution
BIOC WSL Feature Installation Detecting installation of Windows Subsystem for Linux feature. Informational Platform Analytics File Defense Evasion
BIOC Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection