Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
32 detectors match the current filters. tactic: TA0011 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics | A compromised process accessed a rare external host A compromised process accessed a rare external host. | Low | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics | DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Failed DNS The endpoint is performing DNS lookups that are failing at an excessively high rate when compared to its peer group. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics BIOC | Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics | HTTP with suspicious characteristics Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | MpCmdRun.exe was used to download files into the system Attackers might be using legitimate Windows Defender executables to download malicious code onto the system. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Non-browser access to a pastebin-like site Non-browser access to a pastebin-like site. | Low | Platform Analytics | Palo Alto Networks Url Logs | Command and Control |
| BIOC | Plink/SSH reverse tunnel PuTTY link (Plink) / SSH can be used to create encrypted tunnels to communicate back to an attacker's C2 server. | Low | Platform Analytics | Process execution | Command and Control |
| Analytics BIOC | Rare binary connected to a rare cloud resource Rare binary connected to a rare cloud resource. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Rare binary connected to a rare external host Rare binary connected to a rare external host. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Rare communication over email ports to external email server by unsigned process These methods are used by malware and attackers to leak data and remain undetected. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | Suspicious ICMP packet An ICMP router advertisement was sent by a host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| BIOC | Suspicious lock screen image file written to disk Desktopimgdownldr.exe is a built-in Windows tool used to set a lock screen or desktop background image as part of Personalization CSP. Adversaries may use it maliciously to download malware. | Low | Platform Analytics | File | Command and Control |
| Analytics BIOC | Uncommon file access over WebDAV Uncommon file access over WebDAV. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Uncommon SSH session was established An uncommon SSH session was established. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Uncommon VNC server communication Uncommon VNC server network traffic was observed. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Command and Control |