Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

20 detectors match the current filters. tactic: TA0010 ✕ technique: T1048 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
BIOC BitTorrent P2P file sharing The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information. Informational Platform Analytics Dml connection Exfiltration
BIOC Curl connects to an external network Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization. Informational Platform Analytics Network Exfiltration
Analytics BIOC First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. Informational Email Security Microsoft 365 Emails Exfiltration
BIOC Microsoft Office spawns curl/wget on a macOS device Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device. Informational Platform Analytics Process execution Exfiltration
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Possible use of IPFS was detected The host produced traffic consistent with IPFS. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
BIOC Scripting engine makes connections over DNS ports Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. Informational Platform Analytics Network Exfiltration
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Exfiltration
Analytics Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Exfiltration
BIOC Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. Informational Platform Analytics Network Exfiltration
Analytics Unusual attachment volume in outbound emails Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Exfiltration
Analytics BIOC WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. Informational Platform Analytics XDR Agent Exfiltration
BIOC Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. Informational Platform Analytics Network Exfiltration