Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

17 detectors match the current filters. technique: T1548 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC BitLocker key retrieval An identity retrieved a BitLocker Key. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
BIOC Bypassing Windows UAC using sysprep Attackers may use the sysprep.exe built-in Windows tools to bypass Windows UAC. Informational Platform Analytics Process execution Privilege Escalation
BIOC Command enumeration via sudo The 'sudo -l' command was executed to enumerate commands that can be executed by a user. Informational Platform Analytics Process execution Privilege Escalation
Analytics BIOC Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Device Registration Policy modification An identity changed the Device Registration policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
BIOC Discovery of files with setgid or setuid bits Attackers may try to locate files with setgid or setuid bits set to escalate privileges. Informational Platform Analytics Process execution Privilege Escalation
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
BIOC Manipulation of MMC Registry configuration Creation or modification of these Microsoft Management Console related entries can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics Registry Privilege Escalation
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
BIOC Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. Informational Platform Analytics Process execution Privilege Escalation
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
Analytics BIOC Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Tampering with the Windows User Account Controls (UAC) configuration EnableLUA specifies whether Windows User Account Controls (UAC) notifies the user when programs try to modify the computer. UAC was formerly known as Limited User Account (LUA). Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual Conditional Access operation for an identity An identity attempted to add or update an Azure AD Conditional Access policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
BIOC Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. Informational Platform Analytics Process execution Privilege Escalation