Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. technique: T1059 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | 64-bit PowerShell spawning a 32-bit PowerShell Malware typically spawns 32-bit processes to work on as many hosts as possible. This case is therefore suspicious when it happens on a 64-bit host. | Low | Platform Analytics | Process execution | Execution |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. | Low | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access, Execution |
| Analytics BIOC | Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Download a script using the python requests module Download a shell script from a remote location using the Python requests module. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | PowerShell Initiates a Network Connection to GitHub PowerShell initiates a Network Connection to GitHub with an uncommon command line. This may have legitimate uses, but this technique is frequently used by attackers to serve malicious payloads. | Low | Platform Analytics | Palo Alto Networks Url Logs | Execution |
| Analytics BIOC | PowerShell runs suspicious base64-encoded commands Running PowerShell with a base64-encoded payload in the command line is often used by attackers to evade detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Rare process executed by an AppleScript An uncommon process has been executed by the AppleScript interpreter process. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. | Low | Platform Analytics | XDR Agent | Command and Control, Execution |
| Analytics BIOC | Suspicious PowerShell Command Line Attackers often leverage PowerShell one-liners, in which PowerShell is executed with suspicious options on the command line. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Uncommon AppleScript containing a potential obfuscation technique was executed The AppleScript interpreter process was executed with an obfuscation technique in the command line. | Low | Platform Analytics | XDR Agent | Execution, Defense Evasion |
| Analytics BIOC | Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line The AppleScript interpreter was executed with a script designed to capture screen content or clipboard data. | Low | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords The AppleScript interpreter potentially utilizes credential-grabbing techniques to steal user passwords. | Low | Platform Analytics | XDR Agent | Execution, Credential Access |
| Analytics BIOC | Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. | Low | Platform Analytics | XDR Agent | Execution, Exfiltration |
| Analytics BIOC | Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |