Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
24 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A remote service was created via RPC over SMB A remote service was created via RPC over SMB. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics | Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics | Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics | Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon executable was remotely written over SMB to an uncommon destination An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Rare file transfer over SMB protocol The endpoint performed an abnormal file transfer over SMB to a remote host. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Persistence |
| Analytics BIOC | Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics BIOC | Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | RDP connections enabled remotely via Registry An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| BIOC | RDP connections enabled via Registry by unsigned process An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Low | Platform Analytics | Registry | Lateral Movement |
| Analytics BIOC | RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Lateral Movement |
| Analytics BIOC | Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |
| Analytics BIOC | Uncommon VNC server communication Uncommon VNC server network traffic was observed. | Low | Platform Analytics | XDR Agent | Command and Control, Lateral Movement |
| Analytics BIOC | WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |