Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
35 detectors match the current filters. tactic: TA0001 ✕ technique: T1566 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| BIOC | Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. | Informational | Platform Analytics | Process execution | Initial Access |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Display text URL differs from actual URL An email contains a hyperlink whose display text shows a URL different from the actual destination URL. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email mimics replies or forwards without an actual ongoing conversation An email with a subject line or body that includes signs of a reply or forward without an actual ongoing conversation. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Email sent using an automated system or script detected The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| BIOC | Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. | Informational | Platform Analytics | File | Initial Access |
| Analytics BIOC | External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | Numerous emails sent by a single sender to multiple internal recipients Numerous emails were sent to multiple internal recipients. This may indicate spam or any other malicious attempt. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| BIOC | Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. | Informational | Platform Analytics | File | Initial Access |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion |
| Analytics BIOC | Quarantined email released to recipients This message was previously quarantined by vendor and has now been released and delivered to the intended recipients. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics | Suspicious sender exhibiting automated sending patterns Multiple messages from a single sender were observed over a short period, all having the same subject and differing body content. This repetitive pattern may indicate automated or scripted behavior. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics | Suspicious sending domain with sender address randomization Multiple messages from a single sender domain were observed over a short period, each using a unique sender address. This per-message sender randomization is uncommon for legitimate senders and suggests automated behavior. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unrecognized internal address (AAD mismatch) An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Unusual display name in From header An email was detected with an unusual display name in the From header. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion, Execution |