Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1088 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Ping to localhost from an uncommon, unsigned parent process Ping is often used by malware and attackers to delay the execution of suspicious commands in sandbox environments. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Privilege Escalation
BIOC Pluggable Authentication Modules Access Access to Pluggable Authentication Modules. Informational Platform Analytics Process execution Credential Access
BIOC Pluggable Authentication Modules Modification Modification of Pluggable Authentication Modules. Informational Platform Analytics File Credential Access
Analytics Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls Discovery
Analytics Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
BIOC Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). Informational Platform Analytics Process execution Discovery
BIOC Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. Informational Platform Analytics Process execution Discovery
Analytics BIOC Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible binary padding using dd A suspicious dd command ran and added data to a binary. This may indicate binary padding to change the hash of a file. Informational Platform Analytics XDR Agent Defense Evasion
Analytics Possible Brute Force in universal authentication An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack. Informational Identity Analytics Credential Access, Resource Development
Analytics Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. Informational Platform Analytics XDR Agent Credential Access
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Credential Access, Execution
BIOC Possible data destruction via dd Attackers may use dd to zero out or write random data to files. Informational Platform Analytics Process execution Impact
Analytics Possible data exfiltration over a USB storage device A process generated massive file creation, renaming and write activity to a USB storage device. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC Possible data obfuscation A command that can be used for file obfuscation was executed with an uncommon command line. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. Informational Platform Analytics XDR Agent Collection
Analytics BIOC Possible GPO Enumeration A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Resource Development
Analytics Possible internal data exfiltration over a USB storage device A user generated abnormal massive file activity to a connected USB storage device. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Possible log destruction using the dd command Possible destruction of system log files using the dd command. Informational Platform Analytics File Defense Evasion
Analytics Possible Password Spray in universal authentication An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack. Informational Identity Analytics Credential Access, Resource Development
Analytics Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible TGT reuse from different hosts (pass the ticket) We observed two different hosts sending TGS using the same TGT. This may indicate a TGT was stolen and passed to another host. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Possible use of IPFS was detected The host produced traffic consistent with IPFS. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
BIOC Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. Informational Platform Analytics Process execution Discovery
BIOC Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. Informational Platform Analytics Process execution Discovery
BIOC Possible web shell command execution Possible command execution via a web shell for reconnaissance. Informational Platform Analytics Process execution Persistence
BIOC Possible XDG autostart persistency Possible persistency gained by writing or creating a desktop file inside the xdg autostart directory. Informational Platform Analytics File Persistence
Analytics BIOC Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. Informational Cortex Cloud AWS Audit Log Persistence, Credential Access, Lateral Movement
Analytics BIOC Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Credential Access
BIOC Potential Network Sniffing Network sniffing related processes were detected. Informational Platform Analytics Process execution Credential Access, Discovery
Analytics Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics BIOC Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Collection, Initial Access
Analytics BIOC Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. Informational Email Security Microsoft 365 Emails Initial Access, Defense Evasion
BIOC Potential web shell installation A web-app script file was installed on a web server. This can indicate an installation of web shell. Informational Platform Analytics File Persistence
BIOC PowerShell calling Invoke-Expression argument These PowerShell arguments are often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
BIOC PowerShell is used to execute a CPL file Attackers may use PowerShell.exe to execute a CPL file to achieve Control Panel proxy execution. Informational Platform Analytics Process execution Defense Evasion
BIOC PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC PowerShell possibly attempting to execute as administrator This PowerShell argument is often used to run commands with malicious intent. Informational Platform Analytics Process execution Execution
BIOC PowerShell running with download in the command line PowerShell can be used to download malicious content from the internet. Informational Platform Analytics Process execution Execution
BIOC PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. Informational Platform Analytics Process execution Collection
BIOC Print spooler set to load new DLL on boot Malware can use this technique to load malicious code at startup that will persist on system reboot. This DLL must be located in C:\Windows\System32 and will be loaded by the print spooler service, spoolsv.exe, on boot. A port monitor can be set through the AddMonitor API. Informational Platform Analytics Registry Persistence
Analytics BIOC Privileged certificate request via certificate template A privileged certificate was requested via certificate template. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec executed with plain-text credentials on the command line PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands. Informational Platform Analytics Process execution Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
BIOC PsExec runs with System privileges PsExec.exe is a Windows administrative tool, it can be used to elevate privileges and run other processes with NT/System privilege level. Informational Platform Analytics Process execution Privilege Escalation
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
BIOC Psexesvc.exe executes a command from a remote host Psexesvc.exe executes to run a command received from a remote host via PsExec. Informational Platform Analytics Process execution Execution
Analytics BIOC Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Quarantined email released to recipients This message was previously quarantined by vendor and has now been released and delivered to the intended recipients. Informational Email Security Microsoft 365 Emails Initial Access
BIOC Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. Informational Platform Analytics Process execution Discovery, Execution
BIOC Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. Informational Platform Analytics Process execution Collection
Analytics Rare access to known advertising domains The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Persistence
Analytics BIOC Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol A process made a connection to an external IP address or host that is rarely connected to by the organization. Informational Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Rare LOLBIN Process Execution by User A user executed a living-off-the-land binary (LOLBIN) process that is unusual for this user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare machine account creation A user was observed creating a machine account for the first time. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Rare MS-Update Server was detected The endpoint requested an MS-Update operation from a rare update server. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access
Analytics BIOC Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare NTLM Access By User To Host An unusual NTLM authentication attempt by a user to a host. This may indicate the use of stolen credentials or access tokens to access restricted hosts. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Rare NTLM Usage by User Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare scheduled task created A new rare scheduled task was created with a rare path and a rare command line. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics BIOC Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
BIOC RDP connections enabled via Registry from a script host or rundll32.exe An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Informational Platform Analytics Registry Lateral Movement
BIOC Reading .ssh files Attackers may gather SSH keys (typically found in the ~/.ssh/ directory) to later use to authenticate with remote SSH servers. Informational Platform Analytics Process execution Credential Access
BIOC Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. Informational Platform Analytics Process execution Discovery
Analytics BIOC Registration of Uncommon .NET Services and/or Assemblies Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Registry credentials extraction Attackers may extract credentials from the Registry using system commands. Informational Platform Analytics Process execution Credential Access
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. Informational Platform Analytics XDR Agent Execution
BIOC Remote file copy Remote copy operation of a file using rsync or scp or sftp. Informational Platform Analytics Process execution Lateral Movement
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Remote RDP session enumeration via query.exe Attackers may use the built-in query.exe tool to enumerate remote sessions, using the session flag. Informational Platform Analytics Process execution Lateral Movement