Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

50 detectors match the current filters. tactic: TA0008 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user authenticated with weak NTLM to multiple hosts A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days. Informational Identity Analytics XDR Agent Lateral Movement
Analytics A user established an SMB connection to multiple hosts A user established an SMB connection to multiple hosts. This might indicate an enumeration attempt by a compromised account. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics BIOC An identity started an AWS SSM session An identity started an AWS SSM interactive session. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC AWS SSM send command attempt An identity executed an AWS SSM Document. Informational Cortex Cloud AWS Audit Log Lateral Movement, Execution
Analytics BIOC Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. Informational Cortex Cloud Azure Audit Log Defense Evasion, Lateral Movement
Analytics BIOC Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. Informational Cortex Cloud Azure Audit Log Execution, Lateral Movement
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics BIOC Cloud email service activity A cloud Identity performed an email service operation. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Lateral Movement
BIOC Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. Informational Platform Analytics Process execution Lateral Movement, Execution
Analytics BIOC DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
BIOC Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. Informational Platform Analytics File Lateral Movement
BIOC Manipulation of RDP settings Possible modification of Terminal Services/RDP settings. Informational Platform Analytics Registry Lateral Movement
Analytics Multiple alerts associated with a single RDP connection Multiple alerts associated with a single RDP connection were triggered. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Lateral Movement
Analytics Multiple users authenticated with weak NTLM to a host Multiple user accounts authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be a result of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that NTLM authentication data has been relayed. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Privilege Escalation
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Possible TGT reuse from different hosts (pass the ticket) We observed two different hosts sending TGS using the same TGT. This may indicate a TGT was stolen and passed to another host. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. Informational Cortex Cloud AWS Audit Log Persistence, Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack Multiple NTLM authentications were made to the same workstation and user from different IPs. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server Multiple NTLM authentications were made to the same Microsoft Configuration Manager site server and user from different IPs in a short period of time. This might indicate a potential NTLM Relay attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
Analytics BIOC Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare MS-Update traffic over HTTP The endpoint requested an MS-Update operation with abnormal HTTP traffic characteristics. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare NTLM Access By User To Host An unusual NTLM authentication attempt by a user to a host. This may indicate the use of stolen credentials or access tokens to access restricted hosts. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Rare NTLM Usage by User Rare authentication by user account to host via NTLM. The user has not authenticated with NTLM in the past 30 days. This may be indicative of downgrade attacks from Kerberos to NTLM. Informational Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. Informational Platform Analytics XDR Agent Lateral Movement
BIOC RDP connections enabled via Registry from a script host or rundll32.exe An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Informational Platform Analytics Registry Lateral Movement
BIOC Remote file copy Remote copy operation of a file using rsync or scp or sftp. Informational Platform Analytics Process execution Lateral Movement
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Remote RDP session enumeration via query.exe Attackers may use the built-in query.exe tool to enumerate remote sessions, using the session flag. Informational Platform Analytics Process execution Lateral Movement
BIOC Remote RDP session enumeration via qwinsta.exe Attackers may use the built-in qwinsta.exe tool to enumerate remote sessions. Informational Platform Analytics Process execution Lateral Movement
Analytics BIOC Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Lateral Movement
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. Informational Cortex Cloud AWS Audit Log Discovery, Lateral Movement
Analytics BIOC Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. Informational Platform Analytics XDR Agent Initial Access, Lateral Movement
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics BIOC Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics User sent messages in Microsoft Teams to multiple conversations via Graph API A user who rarely uses the Graph API for Microsoft Teams messaging sent multiple messages using it. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Microsoft Graph Logs Lateral Movement