Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
22 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Successful login from TOR A successful login from a TOR exit node. | High | Identity Analytics | XDR Agent | Initial Access, Command and Control |
| Analytics BIOC | A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. | High | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Command and Control |
| Analytics BIOC | A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. | High | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access, Command and Control |
| Analytics BIOC | Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. | High | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics BIOC | Collection error A collection error was detected. | High | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. | High | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | PowerShell used to remove mailbox export request logs An attacker may use PowerShell to remove evidence of an export request for a mailbox as part of the clean-up stage. | High | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. | High | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Command and Control |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics BIOC | Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. | High | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Command and Control |
| Analytics BIOC | Suspicious usage of File Server Remote VSS Protocol (FSRVP) A suspicious usage of File Server Remote VSS Protocol (FSRVP) was done. | High | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Unicode RTL Override Character An attacker may use a special right-to-left (RTL) override character to trick users into executing malicious files that look like benign file types. | High | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Wbadmin deleted files in quiet mode Wbadmin was used to delete files in quiet mode. | High | Platform Analytics | XDR Agent | Impact |