Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. tactic: TA0004 ✕ technique: T1548 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | LOLBIN process executed with a high integrity level A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. | Low | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. | Low | Platform Analytics | Windows Event Collector, XDR Agent | Privilege Escalation |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| BIOC | WSReset.exe UAC bypass Attackers may use WSReset.exe to bypass User Account Control (UAC). | Low | Platform Analytics | Process execution | Privilege Escalation |