Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
23 detectors match the current filters. technique: T1036 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics BIOC | A LOLBIN was copied to a different location To evade detection, attackers may copy a LOLBIN executable to a different location. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A process is masquerading as a common Microsoft product An attacker might leverage common Microsoft software image names to run malicious processes without being caught. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Common Apple process name missing Apple digital signature These common Apple process names should normally be signed with the Apple Inc. digital signature. Naming processes with common names is a common way attackers obfuscate their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Common Mozilla process name missing Mozilla digital certificate These common Mozilla process names should normally be signed with the Mozilla Corporation digital signature. Naming processes with common names is a common way attackers obfuscate their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. | Informational | Email Security | Microsoft 365 Emails | Execution, Defense Evasion |
| Analytics BIOC | Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Executable moved to Windows system folder An attacker may be trying to avoid detection by moving an executable to a Windows system folder. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Execution of masqueraded third-party utility An attacker may be trying to avoid detection of third-party utility execution by renaming it. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Execution of renamed lolbin An attacker may be trying to avoid detection of lolbin's execution using a renamed lolbin. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | File renamed to have a script extension Adversaries may create 'benign-looking' files, which are later used as malicious scripts by changing their extension. | Informational | Platform Analytics | File | Defense Evasion |
| Analytics BIOC | Punycode characters detected in URL(s) Punycode character(s) detected within URL(s) in email content. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| BIOC | Shell binary copied to another location Attackers may try to evade detection by copying the shell binary to an innocent-looking name. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Space after filename A file was created or renamed to have a space at the end of its name. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Space after filename creation An attacker may append a space to the end of a filename to change how it's processed by the operating system. | Informational | Platform Analytics | File | Defense Evasion |
| Analytics BIOC | Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. | Informational | Platform Analytics | XDR Agent | Command and Control, Defense Evasion |
| Analytics BIOC | Suspicious Unicode character detected in email Unicode characters can be used for obfuscation, allowing malicious actors to disguise harmful intent, URLs or attachments By embedding non-printing Unicode characters, attackers can bypass security filters and evade detection mechanisms Such characters may also be used for phishing attempts that appear legitimate to both users and security systems. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Usage of homograph characters detected in an email Detected characters resembling Latin letters within an email's subject and/or body. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Usage of homograph characters detected in an email's from header Detected characters resembling Latin letters within an email's From header. This could indicate an attempt to impersonate a well-known brand or impersonate someone's identity. This could also be used as a method to evade text scanners and analyzers. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| BIOC | Windows process masquerading by an unsigned process A process is trying to disguise itself as a legitimate Windows process, but is unsigned. This usually indicates malicious activity. | Informational | Platform Analytics | Process execution | Defense Evasion |