Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1088 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Massive files deletion in Box A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Box Audit Log Impact
Analytics Massive files deletion in Dropbox A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) DropBox Impact
Analytics Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Google Workspace Audit Logs Impact
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
Analytics Massive upload to a rare storage or mail domain A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent Exfiltration
Analytics Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Exfiltration, Collection
Analytics BIOC Member added to a Windows local security group A member was added to a Windows local security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. Informational Identity Analytics XDR Agent Credential Access, Privilege Escalation
BIOC Microsoft HTML Application Host spawns from CMD or PowerShell Microsoft HTML Application Host is a program whose source code consists of HTML, Dynamic HTML and a few scripting languages compatible with Internet Explorer such as VBScript or JScript. It does not typically spawn from PowerShell or CMD. Informational Platform Analytics Process execution Defense Evasion
BIOC Microsoft HTML Application Host spawns from Explorer.exe Mshta allows execution of .hta files, an attacker can use mshta to execute malicious hta files on the victim's host. Informational Platform Analytics Process execution Defense Evasion
BIOC Microsoft Office executes an unsigned process in a suspicious directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns a commonly abused process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office process spawns an unsigned process Common weaponized office document behavior. Informational Platform Analytics Process execution Execution
BIOC Microsoft Office spawns curl/wget on a macOS device Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device. Informational Platform Analytics Process execution Exfiltration
Analytics Microsoft OneDrive enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneDrive items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneNote enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneNote items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft SharePoint enumeration activity The Microsoft Graph API was used to enumerate Microsoft SharePoint sites in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Persistence
Analytics Microsoft Teams enumeration activity The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
BIOC Modification of default Windows startup path via Registry An attacker may modify the startup path to the location of the malware. Informational Platform Analytics Registry Persistence
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
BIOC Modification of systemd service files An attacker may create or modify systemd service unit files to establish persistence between reboots. Informational Platform Analytics File Persistence
Analytics BIOC Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Defense Evasion
BIOC Modification of the Winlogon\Shell Registry key Malware may modify the Winlogon\Shell Registry value to load itself instead of explorer.exe, which is the default system shell. Informational Platform Analytics Registry Persistence
BIOC Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. Informational Platform Analytics Process execution Defense Evasion, Impact
Analytics BIOC Modification or Deletion of an Azure Application Gateway Detected Modification or Deletion of an Azure Application Gateway Detected. A change has been detected in an Azure Application Gateway. This may indicate unauthorized access or malicious activity. Informational Cortex Cloud Azure Audit Log Persistence
BIOC Modifying ELF file capabilities via setcap An attacker may attempt to gain privileges by setting the capabilities of a file. Informational Platform Analytics Process execution Privilege Escalation
Analytics BIOC Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. Informational Email Security Microsoft 365 Emails Execution, Credential Access
BIOC Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. Informational Platform Analytics Process execution Discovery
BIOC MSBuild execution Attackers may use MSBuild.exe to proxy execution of code through a trusted Windows utility. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC MSI accessed a web page running a server-side script The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Msiexec execution of an executable from an uncommon remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Informational Platform Analytics XDR Agent Defense Evasion
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics Multiple alerts associated with a single RDP connection Multiple alerts associated with a single RDP connection were triggered. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Lateral Movement
Analytics Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Multiple Okta MFA requests sent to a user Multiple SSO MFA attempts were sent to the user. This may indicate an MFA fatigue attack. Informational Identity Analytics Okta Credential Access, Resource Development
Analytics Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics Multiple TGT requests for users without Kerberos pre-authentication Multiple TGT requests for users that do not require Kerberos pre-authentication were observed. This is typically a sign of an AS-REP attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Multiple user accounts were deleted A user deleted multiple user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Impact
Analytics Multiple users authenticated with weak NTLM to a host Multiple user accounts authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be a result of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC Near-empty email from an external sender The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context. Informational Email Security Microsoft 365 Emails Reconnaissance
BIOC Netcat shell via named pipe Attackers may create a Netcat shell using a named pipe to remotely access the endpoint. Informational Platform Analytics Process execution Execution
BIOC Netrc file enumeration Enumeration commands such as test and cat were executed on .netrc file paths that contain credentials. Informational Platform Analytics Process execution Credential Access
BIOC Netsh.exe modifies allowed firewall port/program lists Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use. Informational Platform Analytics Process execution Defense Evasion
BIOC Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. Informational Platform Analytics Process execution Discovery
BIOC Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. Informational Platform Analytics Process execution Discovery
Analytics BIOC Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access, Discovery
BIOC New certificate added to the trusted root store Untrusted certificates could be used to install untrusted drivers and malicious code. Informational Platform Analytics Process execution Defense Evasion
BIOC New entry added to startup related Registry keys by unsigned process Entries added to the "Run Keys" in the Registry or the startup folder will cause the program to be executed when the user logs in. The program will be executed in the context of the user and will have his permissions level. Informational Platform Analytics Registry Persistence
BIOC New service created via command line Attackers may leverage services to gain persistence on an endpoint. Informational Platform Analytics Process execution Persistence
Analytics BIOC New Teams application published to the organization catalog A new Teams application was published to the organization catalog. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
BIOC Non-browser process downloads content from GitHub Check for possible attempts to use GitHub as a malicious payload deployment mechanism. This technique is known to be used frequently by threat actors to serve malicious scripts/payloads. Informational Platform Analytics Network Command and Control
Analytics NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics Numerous emails sent by a single sender to multiple internal recipients Numerous emails were sent to multiple internal recipients. This may indicate spam or any other malicious attempt. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Object versioning was disabled Object versioning of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Impact
BIOC Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. Informational Platform Analytics Process execution Initial Access
BIOC Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. Informational Platform Analytics Process execution Initial Access
BIOC Office process writes an executable file to disk An executable file was written by a Microsoft Office application to disk. Informational Platform Analytics File Execution
Analytics Okta account reset password attempt A user used a weak factor to reset their Okta password. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics Okta account unlock Okta user account was unlocked. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta account unlock by admin An administrative user unlocked an Okta account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta admin privilege assignment A user assigned admin privileges to a new user or group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics Okta device assignment A device was assigned as an Okta MFA device to a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence
Analytics Okta Reported Threat Detected Okta Threat Insight Reported Threat Detected. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta User Session Impersonation A user has initiated a session impersonation in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC OneDrive file download A file was downloaded from OneDrive using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics BIOC OneDrive file upload A file was uploaded to OneDrive using Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Resource Development
Analytics BIOC OneDrive folder creation A folder was created in OneDrive using Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
BIOC Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. Informational Platform Analytics File Initial Access
Analytics BIOC Owner added to Azure application An identity was added as an owner to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
BIOC Password complexity enumeration Attackers may read system files containing password complexity requirements. Informational Platform Analytics Process execution Discovery
BIOC Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. Informational Platform Analytics Process execution Discovery
BIOC Password-related Mozilla files were read by a non-Mozilla process Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Informational Platform Analytics File Credential Access
Analytics BIOC Penetration testing tool activity attempt A SaaS API was invoked by a penetration testing tool. Informational Identity Analytics Office 365 Audit Execution
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
BIOC Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. Informational Platform Analytics Process execution Discovery
BIOC Permissive file privileges were granted Setting readable, writable, and executable permissions for all users may pose a major security risk. Informational Platform Analytics Process execution Defense Evasion
BIOC Persistence through service registration An attacker may add or modify system services to persist on a host. Informational Platform Analytics File Persistence
BIOC Persistence using bashrc files Possible persistency using shell (bash\csh) profile files. Commands in ~/.bashrc are executed on every new shell execution. Informational Platform Analytics File Persistence
BIOC Persistence using cron jobs Cron jobs are tasks to be executed sometime in the future, and could be used to persist malware. Informational Platform Analytics File Persistence
BIOC Persistence via Registry screensaver key change Attackers may install their malware persistently by modifying the value of the screensaver Registry key. Informational Platform Analytics Registry Persistence
Analytics BIOC PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. Informational Cortex Cloud Azure Audit Log Impact
BIOC Ping executed with loopback address This seemingly strange "wait" mechanism is often used by malware to stall command execution. Informational Platform Analytics Process execution Defense Evasion
BIOC Ping to a known external IP address Pinging a known external IP address is often used by malware to check internet connectivity. Informational Platform Analytics Process execution Defense Evasion