Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
255 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | SSH key pair discovery Attackers may look for SSH key pairs using the find command. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| BIOC | Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. | Informational | Platform Analytics | File | Discovery |
| BIOC | Suspicious file created in AppData directory A suspicious executable file was created in the AppData directory. | Informational | Platform Analytics | File | Execution |
| BIOC | Suspicious process loads AMSI DLL Amsi.dll is expected to be loaded from a few known processes (e.g. PowerShell). An image load from an unrelated LOLBIN may indicate PowerShell execution. | Informational | Platform Analytics | Module | Execution |
| BIOC | Suspicious SDB file written to disk Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files may be indicative of this technique. | Informational | Platform Analytics | File | Persistence |
| BIOC | Suspicious SDB file written to disk by an unsigned process Application Shims were created to allow backward compatibility of applications, which can be abused to establish persistence or elevate privileges. The creation of SDB (Shim Database) files by an unsigned process may be indicative of this technique. | Informational | Platform Analytics | File | Persistence |
| BIOC | Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | SyncAppvPublishingServer used to run PowerShell code SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System network configuration discovery System network configuration discovery using Linux command-line utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System owner/user discovery System owner/user discovery using bash utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Tampering with Windows Security Support Provider DLLs Windows Security Support Provider (SSP) DLLs are loaded into the Local Security Authority (LSA) process at system start. Once loaded into the LSA, SSP DLLs have access to encrypted and plaintext passwords that are stored on Windows, such as any logged-on user's Domain password etc. CurrentControlSet is replaced with * because it can be replaced with ControlSet001 or ControlSet002. | Informational | Platform Analytics | Registry | Persistence |
| BIOC | Task scheduled by commonly abused host process Attackers will often attempt to abuse shell/host processes to create a persistent payload in the form of a scheduled task. Check for malicious use. | Informational | Platform Analytics | Process execution | Persistence |
| BIOC | The scripting engine executed code from an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. An attacker may try to evade detection by executing malware from the ADS value of a file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Unsigned process accessed a credential locker file The credential manager stores credentials for logging in to websites, applications and devices in encrypted Windows Vault Credential Files which can be accessed and decrypted by an attacker. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process accessed a Thunderbird Mail profiles folder An attacker may access the Thunderbird Mail profiles folder to extract users' credentials. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process creates an Alternate Data Stream (ADS) Alternate Data Streams (ADSs) are NTFS Master File Table (MFT) data entries that relate to a file, but are separate from its contents. Malware may attempt to evade discovery by placing their payload in an ADS. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | Unsigned process injects code into a process An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack. | Informational | Platform Analytics | Remote code | Defense Evasion |
| BIOC | Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| BIOC | Unsigned process reads Chromium credentials file Adversaries may acquire credentials from web browsers by reading files specific to the target browser. | Informational | Platform Analytics | File | Credential Access |
| BIOC | Unsigned process running from a temporary directory Malware often runs from a temporary folder. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Unusual process spawned by fontdrvhost.exe A remote code execution vulnerability (CVE-2020-1020) exists in the Windows Adobe Type Manager Library. An unusual process spawned by fontdrvhost.exe can be a possible indicator of exploitation. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | Usage of tracing tool An attacker may be trying to use a known tracing tool to gather information from other processes. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. | Informational | Platform Analytics | File | Persistence |
| BIOC | VBScript execution from the command line Attackers may run VBScript code from the command line using signed processes such as Mshta. | Informational | Platform Analytics | Process execution | Execution |
| BIOC | VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Web browser cookie and credential access Detect attempt to acquire cookies or credentials from a Safari browser. | Informational | Platform Analytics | Process execution | Credential Access |
| BIOC | Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. | Informational | Platform Analytics | Network | Exfiltration |
| BIOC | Windows 10 Developer Mode enabled Enabling developer mode allows for app sideloading and starts the Windows SSH services, which may be used to install Linux Bash on Windows. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. | Informational | Platform Analytics | File | Collection |
| BIOC | Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. | Informational | Platform Analytics | Windows event log | Defense Evasion |
| BIOC | Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |
| BIOC | WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. | Informational | Platform Analytics | Process execution | Credential Access, Impact |
| BIOC | WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. | Informational | Platform Analytics | Process execution | Defense Evasion, Execution |
| BIOC | Write to .bash_profile Commands in ~/.bash_profile are executed on every user shell login with a username and password. | Informational | Platform Analytics | File | Persistence |
| BIOC | Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. | Informational | Platform Analytics | File | Discovery |
| BIOC | Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Wscript.exe connects to an external network It may be due to local IT or administrative tools used on endpoints, but it could also indicate exfiltration of data between hosts in the local network, malware droppers, beaconing and so on. The execution chain should be reviewed to determine the context of the activity. | Informational | Platform Analytics | Network | Execution |
| BIOC | WSL Feature Installation Detecting installation of Windows Subsystem for Linux feature. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |