Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1088 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. Informational Platform Analytics Process execution Discovery, Execution
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
BIOC Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. Informational Platform Analytics Process execution Defense Evasion, Discovery
BIOC Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. Informational Platform Analytics File Initial Access
Analytics BIOC Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
BIOC Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. Informational Platform Analytics File Lateral Movement
Analytics BIOC Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Execution of an uncommon process at an early startup stage Uncommon execution of an executable found in an early startup stage. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process with a local/domain user SID at an early startup stage Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused. Informational Platform Analytics XDR Agent Persistence
BIOC Execution of commonly abused AutoIT script AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Execution of regsvcs/regasm with uncommon paths The regasm.exe/regsvcs.exe commands are used to register .NET COM assemblies, which are typically located in specific paths. Uncommon paths may indicate malicious code is being registered. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Execution of WSL Distro Detecting a new instance execution of Windows Subsystem for Linux distro. Informational Platform Analytics File Defense Evasion
Analytics BIOC External email display name impersonation of internal personnel Potential email attempting to impersonate an internal user has been detected. The sender's email address appears unusual in relation to the provided display name, suggesting a possible impersonation attempt targeting an internal user. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics BIOC External Sharing was turned on for Google Drive An identity has modified Google Drive sharing settings and allowed external sharing. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Exfiltration
Analytics BIOC External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics BIOC External user invitation to Azure tenant An external user was invited to Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
BIOC File renamed to have a script extension Adversaries may create 'benign-looking' files, which are later used as malicious scripts by changing their extension. Informational Platform Analytics File Defense Evasion
BIOC File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC First connection from a country in organization A user connected to an SSO service from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC First SSO access from ASN for user A user successfully authenticated via SSO with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO access from ASN in organization An SSO authentication was made with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Discovery
Analytics BIOC First VPN access attempt from a country in organization A user attempted to connect from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC First VPN access from ASN for user A user logged in to a VPN with a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC First VPN access from ASN in organization A VPN connection was attempted from a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. Informational Email Security Microsoft 365 Emails Exfiltration
Analytics BIOC First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
BIOC Fltmc.exe used to unload filter driver Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring. Informational Platform Analytics Process execution Defense Evasion
BIOC Fontdrvhost.exe makes network connections A remote code execution vulnerability(CVE-2020-1020) exists in the Windows Adobe Type Manager Library. Network activity of the vulnerable process fontdrvhost.exe can be a possible indicator of exploitation. Informational Platform Analytics Network Execution
Analytics BIOC Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
BIOC Forensics Driver Loaded A forensics driver has been loaded. Informational Platform Analytics Module Collection, Credential Access
Analytics BIOC GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics BIOC GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP set IAM policy activity A cloud identity had modified a resource policy bindings. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Globally uncommon high entropy module was loaded A module with high entropy and a globally uncommon hash was loaded. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon high entropy process was executed A process with high entropy and a globally uncommon hash was executed. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon image load from a signed process A signed process loaded a DLL that, on a global level, it usually doesn't load. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. Informational Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC Globally uncommon IP address by a common process (sha256) A process with a common sha256 connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon process execution from a signed process A signed process has executed a process that, on a global level, it usually doesn't execute. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Globally uncommon root-domain port combination by a common process (sha256) A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Gmail delegation was turned on for the organization A Google Workspace admin turned on Gmail delegation for all the organization's users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Gmail routing settings changed Gmail routing settings were modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC Google Marketplace restrictions were modified An identity modified Google Marketplace Restrictions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Google Workspace automation was created Google Workspace automation was created. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Execution, Persistence, Exfiltration
Analytics BIOC Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC Google Workspace third-party application's security settings were changed An identity changed Google Workspace third-party application's security settings. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
BIOC Grepping for passwords Attackers may look for cleartext passwords in files using the grep command. Informational Platform Analytics Process execution Credential Access
BIOC Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. Informational Platform Analytics Process execution Discovery
BIOC GUI Input Capture Prompt user to supply a password in response to a System Preference dialog pop up message. Informational Platform Analytics Process execution Credential Access
Analytics BIOC Hidden Attribute was added to a file using attrib.exe Hidden attribute was added to a file using attrib.exe, adversaries may set files to be hidden to evade detection mechanisms. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Hidden directory creation Attackers may create hidden directories to hide malware or staged files. Informational Platform Analytics Process execution Defense Evasion
BIOC Hidden file and directory creation Creation of a hidden file inside a hidden directory. Informational Platform Analytics File Defense Evasion