Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
20 detectors match the current filters. technique: T1071 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A compromised process accessed a rare cloud resource A compromised process accessed a rare cloud resource. | Informational | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | A process connected to a rare cloud resource A process connected to a rare cloud resource. | Informational | Platform Analytics | XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | A process connected to a rare external host A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | A process connected to rare external host A process connected to a rare external host. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | An Azure DNS Zone was modified An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration. | Informational | Cortex Cloud | Azure Audit Log | Command and Control |
| BIOC | Direct access to free online DNS servers Online DNS servers are often used to bypass the company's internal DNS servers and evade detection. | Informational | Platform Analytics | Network | Command and Control |
| BIOC | DNS resolution to the Palo Alto Networks sinkhole DNS resolution to the Palo Alto Networks sinkhole. | Informational | Platform Analytics | Network | Command and Control |
| Analytics | Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | Globally uncommon IP address by a common process (sha256) A process with a common sha256 connected to an external IP address that, on a global level, it usually doesn't connect to. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root-domain port combination by a common process (sha256) A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics | Rare access to known advertising domains The endpoint performed many connections to unpopular advertising domains. This could indicate the presence of adware on the endpoint. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Persistence |
| Analytics BIOC | Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol A process made a connection to an external IP address or host that is rarely connected to by the organization. | Informational | Platform Analytics | Palo Alto Networks Url Logs | Command and Control |
| Analytics BIOC | Suspicious curl user agent Suspicious user agent provided to curl command. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Uncommon Linux process communication to a rare external host An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon macOS process communication to a rare external host An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. | Informational | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. | Informational | Platform Analytics | XDR Agent | Command and Control, Exfiltration |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |