Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

8 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC A user modified the CA audit policy A user modified the CA audit policy. This may indicate that an attacker is attempting to cover their tracks before an AD CS attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Certutil pfx parsing Certutil was used to parse a pfx certificate file. Low Platform Analytics XDR Agent Collection
Analytics BIOC LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious Certutil AD CS contact A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface. Low Platform Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Unusual CertLog Remote File Write A remote host wrote to a certificate log file via RPC over SMB, which may indicate the use of an AD CS attack tool like Certipy. This behavior is commonly associated with certificate-based authentication attacks. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC User set insecure CA registry setting for global SANs A user enabled the EDITF_ATTRIBUTESUBJECTALTNAME2 registry flag, allowing custom Subject Alternative Names (SANs) to be specified on all certificate templates. This could enable attackers to bypass security controls by requesting certificates with user-defined SANs. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion