Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1061 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare process execution by user An unusual process was executed by a user. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process execution in organization An unusual process was executed in the organization. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Execution
Analytics BIOC Rare process spawned by srvany.exe Unusual process spawned by srvany.exe, which allows applications to run as services with system privileges, this might be an indication of malicious local or remote code execution. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare scheduled task created A new rare scheduled task was created with a rare path and a rare command line. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare security product signed executable executed in the network Attackers may attempt to install a security product with a known vulnerability to bypass security features. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare service DLL was added to the registry A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics BIOC Rare signature signed executable executed in the network Attackers may use signed executables by less known vendors to bypass security features. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics BIOC Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Rare unsigned process execution by scheduled task Rare and unsigned process was executed by a scheduled task. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC RDP Connection to localhost An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC RDP connections enabled remotely via Registry An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Registration of Uncommon .NET Services and/or Assemblies Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Remote code execution into Kubernetes Pod A container administration service was used to execute commands within a Kubernetes Pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. Informational Cortex Cloud Gcp Audit Log Credential Access
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics BIOC Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. Low Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Remote usage of an Azure Service Principal token An Azure Service Principal token was used externally of the cloud environment. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. Informational Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics BIOC Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. Informational Cortex Cloud Gcp Audit Log Credential Access
Analytics BIOC Remote WMI process execution A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Removal of an Azure Owner from an Application or Service Principal An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Retrieval of cloud compute EC2 instance user data A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. Informational Cortex Cloud AWS Audit Log Collection
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Run downloaded script using pipe Downloading a script using wget or curl and executing it using a pipe to a shell. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Rundll32.exe executes a rare unsigned module Rundll32.exe executes a rare unsigned module, which can indicate an attacker's malicious execution. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe running with no command-line arguments Rundll32.exe is meant to run with parameters, so the absence of them is extremely suspicious; this behavior is used in the default configuration of Cobalt Strike. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Rundll32.exe spawns conhost.exe This unusual parent-child process relationship may indicate that an attacker has abused rundll32.exe to run a console-based application such as PowerShell. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. Informational Email Security Office 365 Audit Collection
Analytics BIOC SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Initial Access
Analytics BIOC Scheduled Task hidden by registry modification Attackers may try to hide a Scheduled Task by deleting the Scheduled Task's software descriptor (SD) value in the registry. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Screensaver process executed from Users or temporary folder An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Script file added to startup-related Registry keys An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics BIOC SecureBoot was disabled SecureBoot was disabled, this might be indicative of someone trying to install an alternate non-UEFI supported OS. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC Sending unusual file(s) to an external address Unusual files sent to an external address. Low Email Security Microsoft 365 Emails Initial Access, Exfiltration
Analytics BIOC Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics BIOC Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC Service execution via sc.exe Sc.exe has the ability to start services on local and remote hosts. An attacker may abuse it to execute malicious services on a host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC SES Production Access Requested An identity requested to move the SES account from a restricted sandbox mode into production mode. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. Low Platform Analytics XDR Agent Privilege Escalation, Defense Evasion
Analytics BIOC SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Signed process creates a scheduled task via file access A signed process created a scheduled task via file access. Attackers may create scheduled tasks for execution and to establish persistence. Informational Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC SMB Traffic from Non-Standard Process SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC Space after filename A file was created or renamed to have a space at the end of its name. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC SPNs cleared from a machine account Service principal names were cleared from a machine account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a machine account A machine account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a service account A service account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. Informational Identity Analytics AzureAD, Okta, OneLogin Initial Access
Analytics BIOC SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. Informational Identity Analytics Okta, AzureAD, Azure SignIn Log, Duo, PingOne Initial Access
Analytics BIOC SSO with new operating system A user successfully authenticated via SSO with a new operating system. Informational Identity Analytics Okta, Azure SignIn Log, AzureAD, Duo Initial Access
Analytics BIOC Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. Informational Identity Analytics Initial Access
Analytics BIOC Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious .NET process loads an MSBuild DLL A suspicious process in the Microsoft .NET directory loaded the Microsoft Build Framework DLL. This may occur if an attacker masquerades a process like MSBuild (PowerLessShell). Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Suspicious access of the System Management Container A user accessed the System Management container, which may be an indication of a reconnaissance for site servers. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics BIOC Suspicious access to shadow file An unpopular process accessed the shadow file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious active setup registered The endpoint registered a new active setup, which may be used to gain persistence on the host by loading libraries into the time management service. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. High Cortex Cloud AWS Audit Log, Gcp Audit Log Command and Control