Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

46 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. High Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Command and Control
Analytics BIOC A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. High Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access, Command and Control
Analytics An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. High Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Credential Access
BIOC Bitsadmin.exe used to upload data Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools. High Platform Analytics Process execution Exfiltration, Defense Evasion
Analytics BIOC Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. High Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs Execution
Analytics BIOC Collection error A collection error was detected. High Platform Analytics Health Monitoring Data Impact
BIOC Command-line arguments match Mimikatz execution These command-line arguments are often used by Mimikatz to dump credentials. High Platform Analytics Process execution Credential Access
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
BIOC Credential dumping via LaZagne LaZagne has been executed. Attackers may use this tool to gather account and password information from credential dumping. High Platform Analytics Process execution Credential Access
Correlation Rule DropBox - Massive File Alterations This rule detects more than 100 edited files during an hour by the same user. This is a suspicious behavior which can be an indication of a ransomware attack. High Platform Analytics dropbox_dropbox_raw Impact
Analytics EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. High Cortex Cloud AWS Audit Log Persistence
BIOC Encoded VBScript executed Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding. High Platform Analytics Process execution Execution, Defense Evasion
BIOC EventLog service disabled by a Registry operation A Registry set-value operation that disables the EventLog service was executed on the machine. High Platform Analytics Registry Defense Evasion
BIOC Exchange process writing aspx files An exchange process is writing to .aspx files. This may be an actor dropping web shells. High Platform Analytics File Initial Access, Command and Control
Analytics BIOC Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. High Platform Analytics XDR Agent Credential Access
BIOC Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. High Platform Analytics Process execution Credential Access, Lateral Movement
Analytics BIOC Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. High Platform Analytics XDR Agent Credential Access
Correlation Rule Microsoft Defender for Endpoint - Malware Detected This alert will trigger when Malware is detected by Microsoft Defender for Endpoint. High Enterprise Runtime Security, Cortex Cloud Microsoft Defender Advanced Threat Protection, microsoft_365_defender_raw
Analytics BIOC Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. High Platform Analytics XDR Agent Credential Access
Analytics Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. High Platform Analytics XDR Agent Command and Control
BIOC Ntdsutil.exe accessing ntds.dit file Attackers may attempt to dump ntds.dit, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics File Credential Access
Analytics Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. High Platform Analytics XDR Agent Credential Access
BIOC Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. High Platform Analytics Process execution Execution
Analytics BIOC Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). High Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Possible LSASS memory dump Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. High Platform Analytics Process execution Credential Access
Analytics BIOC PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. High Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Execution
BIOC Process requests the deletion of Windows Shadowcopies Ransomware and wipers may use the wmic.exe or vssadmin.exe utilities to delete or modify Shadowcopies (a Windows backup mechanism). High Platform Analytics Process execution Impact
BIOC Pubprn.vbs signed script proxy execution Pubprn.vbs is a standard script that is installed with Windows that can be abused to run malicious scripts. This behavior may bypass signature validation restrictions and application whitelisting solutions. High Platform Analytics Process execution Defense Evasion
BIOC Regsvr32 may have run code from an untrusted source Regsvr32 may be used to run arbitrary code by passing the '/i' parameter. The code may also be hosted on a remote host. High Platform Analytics Process execution Defense Evasion
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. High Platform Analytics Process execution Execution
BIOC SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. High Platform Analytics Module Initial Access, Command and Control
Analytics BIOC Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. High Cortex Cloud AWS Audit Log, Gcp Audit Log Command and Control
Analytics BIOC Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Command and Control, Initial Access
BIOC Suspicious debug file created in a temporary folder SharpDump and SafetyKatz are credential dumping tools that create minidumps for the process ID (PID) specified (LSASS by default) in C:\Windows\Temp\debug<PID>.bin. High Platform Analytics File Credential Access
Analytics BIOC Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. High Platform Analytics XDR Agent Credential Access
BIOC Suspicious executable created in a .NET directory Cmd.exe created an executable file in the Microsoft .NET directory. This behavior is exhibited in the PowerLessShell tool to disguise MSBuild.exe. High Platform Analytics File Defense Evasion
Analytics Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. High Cortex Cloud AWS Audit Log Impact
Analytics BIOC Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. High Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Command and Control
Analytics BIOC Suspicious usage of File Server Remote VSS Protocol (FSRVP) A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done. High Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. High Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. High Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. High Platform Analytics XDR Agent Impact