Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

55 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC 64-bit PowerShell spawning a 32-bit PowerShell Malware typically spawns 32-bit processes to work on as many hosts as possible. This case is therefore suspicious when it happens on a 64-bit host. Low Platform Analytics Process execution Execution
Analytics BIOC A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A remote service was created via RPC over SMB A remote service was created via RPC over SMB. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
Analytics BIOC A suspicious direct syscall was executed A suspicious direct syscall was executed. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. Low Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Lateral Movement, Execution
Analytics Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Initial Access
Analytics BIOC Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. Low Platform Analytics XDR Agent Execution
Analytics BIOC Download a script using the python requests module Download a shell script from a remote location using the Python requests module. Low Platform Analytics XDR Agent Execution
Analytics BIOC Elevation to SYSTEM via services Services were affected by a non SYSTEM integrity level process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Privilege Escalation
Analytics BIOC Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. Low Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. Low Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Interactive at.exe privilege escalation method Detects an interactive AT scheduled task, which may be used as a form of privilege escalation. Low Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Known service display name with uncommon image-path Service created with a known display name but has an uncommon image-path. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Execution
Analytics BIOC Known service name with an uncommon image-path A Service with a known service name has an uncommon image-path. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Execution
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
BIOC Manipulation of Windows DNS configuration using WMIC This command can be leveraged by attackers to change the way DNS requests are sent, bypassing the corporate DNS servers. Low Platform Analytics Process execution Execution
Analytics BIOC Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics BIOC Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Persistence
Analytics BIOC Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Credential Access
Analytics BIOC PowerShell Initiates a Network Connection to GitHub PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads. Low Platform Analytics Palo Alto Networks Url Logs Execution
Analytics BIOC PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. Low Platform Analytics XDR Agent Execution
Analytics BIOC Rare Unsigned Process Spawned by Office Process Under Suspicious Directory Microsoft Office executed an unsigned process in a suspicious directory. This behavior is common with malicious macros. Low Platform Analytics XDR Agent Execution
BIOC Remote command executed from a Linux host This tool enables commands to be remotely executed on a Microsoft Windows computer from a Linux computer. This capability is leveraged by attackers to run code remotely, similarly to PsExec. Low Platform Analytics Process execution Execution
Analytics BIOC Remote command execution via wmic.exe Remote command execution using the Windows Management Instrumentation command-line tool. Low Platform Analytics XDR Agent Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Scheduled task created with HTTP or FTP reference Scheduled tasks don't normally include web URLs and may indicate malware activity. Low Platform Analytics Process execution Execution
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. Low Cortex Cloud AWS Audit Log, Azure Audit Log Execution
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Suspicious container orchestration job A suspicious orchestration job ran with a rare command line. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Suspicious module load using direct syscall A module was loaded to a process using a direct syscall. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. Low Platform Analytics XDR Agent Execution
Analytics BIOC Suspicious systemd timer activity Suspicious systemd timer activity, which may indicate an attempt to establish persistence. Low Platform Analytics XDR Agent Execution, Persistence, Privilege Escalation
Analytics BIOC Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. Low Platform Analytics XDR Agent Execution, Defense Evasion
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. Low Platform Analytics XDR Agent Execution, Collection
Analytics BIOC Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. Low Platform Analytics XDR Agent Execution, Credential Access
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon remote scheduled task creation The schtasks.exe command enables creating, deleting, querying, changing, running, and ending scheduled tasks on a local or remote computer. Adversaries may attempt to use the command to execute programs or persist malware on remote machines. Low Platform Analytics XDR Agent Execution
Analytics BIOC Uncommon remote service start via sc.exe The Service Control command (sc.exe) is used to create, start, stop, query, or delete Windows services. Adversaries may attempt to use the command to execute and persist a binary, command, or script. Low Platform Analytics XDR Agent Execution
Analytics BIOC Unsigned process creates a scheduled task via file access A scheduled task was created via file access from an unsigned process. This is uncommon and may indicate malicious activity. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution