Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

16 detectors match the current filters. technique: T1218 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Browser downloads an .hta or .application file .hta and .application files are Windows applications that may serve as an attack vector by executing code maliciously using trusted Windows applications. Informational Platform Analytics File Defense Evasion
BIOC Commonly abused process spawns out of rundll32.exe This type of execution happens in .dll based attacks. Informational Platform Analytics Process execution Defense Evasion
BIOC Compiled HTML (help file) makes network connections Compiled HTML (help files) should not normally need to connect to the network. This may have limited legitimate uses, yet this behavior is often observed by malware leveraging malicious CHM files to deliver a 2nd stage payload. Informational Platform Analytics Network Defense Evasion
BIOC Execution of regsvcs/regasm with uncommon paths The regasm.exe/regsvcs.exe commands are used to register .NET COM assemblies, which are typically located in specific paths. Uncommon paths may indicate malicious code is being registered. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Globally uncommon image load from a signed process A signed process loaded a DLL that, on a global level, it usually doesn't load. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. Informational Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Defense Evasion, Command and Control
BIOC Microsoft HTML Application Host spawns from CMD or PowerShell Microsoft HTML Application Host is a program whose source code consists of HTML, Dynamic HTML and a few scripting languages compatible with Internet Explorer such as VBScript or JScript. It does not typically spawn from PowerShell or CMD. Informational Platform Analytics Process execution Defense Evasion
BIOC Microsoft HTML Application Host spawns from Explorer.exe Mshta allows execution of .hta files, an attacker can use mshta to execute malicious hta files on the victim's host. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC MSI accessed a web page running a server-side script The Microsoft installer command line included a URL to a web page running a server-side script, which is suspicious. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Msiexec execution of an executable from an uncommon remote location Msiexec is the command-line utility for the Windows Installer. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads from remote locations. Informational Platform Analytics XDR Agent Defense Evasion
BIOC PowerShell is used to execute a CPL file Attackers may use PowerShell.exe to execute a CPL file to achieve Control Panel proxy execution. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Registration of Uncommon .NET Services and/or Assemblies Regasm.exe and regsvcs.exe are used to register .NET COM assemblies, which are typically located in specific paths, attackers might leverage that to execute code within a Microsoft signed binary. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Rundll32 loads a known abused DLL Rundll32.exe is called to execute an arbitrary binary, this execution may also bypass whitelisting defenses as a signed Microsoft application. Informational Platform Analytics Process execution Defense Evasion
BIOC SyncAppvPublishingServer used to run PowerShell code SyncAppvPublishingServer is part of Microsoft Application Virtualization (App-V), which may be used by an attacker to run PowerShell code. Informational Platform Analytics Process execution Defense Evasion
BIOC Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. Informational Platform Analytics Registry Defense Evasion