Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
17 detectors match the current filters. tactic: TA0011 ✕ technique: T1071 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics | A compromised process accessed a rare external host A compromised process accessed a rare external host. | Low | Platform Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics | DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. | Low | Platform Analytics | XDR Agent | Defense Evasion, Command and Control |
| Analytics BIOC | Rare binary connected to a rare cloud resource Rare binary connected to a rare cloud resource. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Rare binary connected to a rare external host Rare binary connected to a rare external host. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | Uncommon file access over WebDAV Uncommon file access over WebDAV. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Command and Control |
| Analytics BIOC | Uncommon SSH session was established An uncommon SSH session was established. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Command and Control |