Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

4 detectors match the current filters. tactic: TA0008 ✕ technique: T1550 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics BIOC Possible Pass-the-Hash An account was successfully logged on to with new credentials. This login type is rare and may be an attacker's attempt to pass-the-hash and move laterally within a network. Low Identity Analytics XDR Agent Lateral Movement
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics BIOC Suspicious SMB connection from domain controller A domain controller has initiated an SMB connection to another host. The domain controllers usually communicate over SMB only with other domain controllers. An attacker can abuse such sessions for relay attacks. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement