Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
13 detectors match the current filters. technique: T1547 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Active Setup Registry Autostart Suspicious modification of the active setup registry for persistence and privilege escalation. | Low | Platform Analytics | Registry | Persistence |
| Analytics BIOC | Execution of an uncommon process at an early startup stage by Windows system binary Uncommon execution of an executable found in an early startup stage by Windows system binary. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Microsoft Office adds a value to autostart Registry key Microsoft Office adds a value to a registry entry (run keys, startup folders) to establish persistence. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Persistence |
| BIOC | Port Monitor added in Registry Adversaries may use port monitors to run an adversary-supplied DLL during system boot for persistence or privilege escalation. | Low | Platform Analytics | Registry | Persistence |
| BIOC | Print Processor Registration Adversaries may abuse print processors to run malicious DLLs during system boot that will be executed as SYSTEM for privilege escalation and/or persistence. | Low | Platform Analytics | Registry | Persistence |
| Analytics BIOC | Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| BIOC | Suspicious printer driver installation A suspicious process installed a generic printer driver. This may be a sign of CVE-2020-1048, in which an attacker attempts to overwrite a file on the OS. | Low | Platform Analytics | Registry | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious RunOnce Parent Process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user login events. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious runonce.exe parent process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user logon events. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. | Low | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Uncommon Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |