Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
46 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Successful login from TOR A successful login from a TOR exit node. | High | Identity Analytics | XDR Agent | Initial Access, Command and Control |
| Analytics BIOC | A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. | High | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Command and Control |
| Analytics BIOC | A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. | High | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access, Command and Control |
| Analytics | An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. | High | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Credential Access |
| BIOC | Bitsadmin.exe used to upload data Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools. | High | Platform Analytics | Process execution | Exfiltration, Defense Evasion |
| Analytics BIOC | Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. | High | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics BIOC | Collection error A collection error was detected. | High | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. | High | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. | High | Platform Analytics | Process execution | Credential Access |
| Correlation Rule | DropBox - Massive File Alterations This rule detects more than 100 edited files during an hour by the same user. This is a suspicious behavior which can be an indication of a ransomware attack. | High | Platform Analytics | dropbox_dropbox_raw | Impact |
| Analytics | EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. | High | Cortex Cloud | AWS Audit Log | Persistence |
| BIOC | Encoded VBScript executed Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding. | High | Platform Analytics | Process execution | Execution, Defense Evasion |
| BIOC | EventLog service disabled by a Registry operation A Registry set-value operation that disables the EventLog service was executed on the machine. | High | Platform Analytics | Registry | Defense Evasion |
| BIOC | Exchange process writing aspx files An exchange process is writing to .aspx files. This may be an actor dropping web shells. | High | Platform Analytics | File | Initial Access, Command and Control |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. | High | Platform Analytics | Process execution | Credential Access, Lateral Movement |
| Analytics BIOC | Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. | High | Platform Analytics | XDR Agent | Credential Access |
| Correlation Rule | Microsoft Defender for Endpoint - Malware Detected This alert will trigger when Malware is detected by Microsoft Defender for Endpoint. | High | Enterprise Runtime Security, Cortex Cloud | Microsoft Defender Advanced Threat Protection, microsoft_365_defender_raw | |
| Analytics BIOC | Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. | High | Platform Analytics | XDR Agent | Command and Control |
| BIOC | Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | File | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| BIOC | Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | High | Platform Analytics | Process execution | Credential Access |
| Analytics BIOC | PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. | High | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| BIOC | Process requests the deletion of Windows Shadowcopies Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism). | High | Platform Analytics | Process execution | Impact |
| BIOC | Pubprn.vbs signed script proxy execution Pubprn.vbs is a standard script that is installed with Windows that can be abused to run malicious scripts. This behavior may bypass signature validation restrictions and application whitelisting solutions. | High | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Regsvr32 may have run code from an untrusted source Regsvr32 may be used to run arbitrary code by passing the '/i' parameter. The code may also be hosted on a remote host. | High | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| BIOC | Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. | High | Platform Analytics | Process execution | Execution |
| BIOC | SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. | High | Platform Analytics | Module | Initial Access, Command and Control |
| Analytics BIOC | Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Command and Control |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| BIOC | Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. | High | Platform Analytics | File | Credential Access |
| Analytics BIOC | Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | XDR Agent | Credential Access |
| BIOC | Suspicious executable created in a .NET directory Cmd.exe created an executable file in the Microsoft .NET directory. This behavior is exhibited in the PowerLessShell tool to disguise MSBuild.exe. | High | Platform Analytics | File | Defense Evasion |
| Analytics | Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. | High | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. | High | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Command and Control |
| Analytics BIOC | Suspicious usage of File Server Remote VSS Protocol (FSRVP) A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done. | High | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. | High | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. | High | Platform Analytics | XDR Agent | Impact |