Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1061 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Rare scheduled task created A new rare scheduled task was created with a rare path and a rare command line. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare security product signed executable executed in the network Attackers may attempt to install a security product with a known vulnerability to bypass security features. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Persistence |
| Analytics BIOC | Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics BIOC | Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | Rare unsigned process execution by scheduled task Rare and unsigned process was executed by a scheduled task. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | RDP Connection to localhost An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | RDP connections enabled remotely via Registry An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Registration of Uncommon .NET Services and/or Assemblies Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. | Informational | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. | Low | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Remote usage of an Azure Service Principal token An Azure Service Principal token was used externally of the cloud environment. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Remote WMI process execution A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC. | Medium | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Removal of an Azure Owner from an Application or Service Principal An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Retrieval of cloud compute EC2 instance user data A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. | Informational | Email Security | Office 365 Audit | Collection |
| Analytics BIOC | SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Initial Access |
| Analytics BIOC | Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Screensaver process executed from Users or temporary folder An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Script file added to startup-related Registry keys An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | SecureBoot was disabled SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | Sending unusual file(s) to an external address Unusual files sent to an external address. | Low | Email Security | Microsoft 365 Emails | Initial Access, Exfiltration |
| Analytics BIOC | Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics BIOC | Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | SES Production Access Requested An identity requested to move the SES account from a restricted sandbox mode into production mode. | Informational | Cortex Cloud | AWS Audit Log | Resource Development |
| Analytics BIOC | Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| Analytics BIOC | SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | SMB Traffic from Non-Standard Process SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | Space after filename A file was created or renamed to have a space at the end of its name. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | SPNs cleared from a machine account Service principal names were cleared from a machine account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a machine account A machine account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a service account A service account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. | Informational | Identity Analytics | AzureAD, Okta, OneLogin | Initial Access |
| Analytics BIOC | SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. | Informational | Identity Analytics | Okta, AzureAD, Azure SignIn Log, Duo, PingOne | Initial Access |
| Analytics BIOC | SSO with new operating system A user successfully authenticated via SSO with a new operating system. | Informational | Identity Analytics | Okta, Azure SignIn Log, AzureAD, Duo | Initial Access |
| Analytics BIOC | Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. | Informational | Identity Analytics | Initial Access | |
| Analytics BIOC | Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). | Medium | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious access of the System Management Container A user accessed the System Management container, which may be an indication of a reconnaissance for site servers. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Reconnaissance |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious active setup registered The endpoint registered a new active setup, which may be used to gain persistence on the host by loading libraries into the time management service. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Command and Control |