Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
8 detectors match the current filters. tactic: TA0002 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. | High | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| BIOC | Encoded VBScript executed Attackers tend to hide their malicious behavior in many ways, one of which is obfuscating their code via encoding. | High | Platform Analytics | Process execution | Execution, Defense Evasion |
| BIOC | Possible C2 via dnscat2 Dnscat2 creates an encrypted C2 channel over the DNS protocol, which attackers may use to hide traffic. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. | High | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| BIOC | Rubeus tool execution Rubeus is a tool for abusing Kerberos, inspired by Kekeo; its usage may indicate malicious activity. | High | Platform Analytics | Process execution | Execution |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |