Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

71 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A compromised process accessed a rare external host A compromised process accessed a rare external host. Low Platform Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics A user connected a new USB storage device to multiple hosts A user connected a new USB storage device to multiple endpoints. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics A user rejected an SSO request from an unusual country A user rejected an SSO authentication request from an abnormal country. Low Identity Analytics Okta, OneLogin Credential Access, Resource Development
Analytics A user sent multiple TGT requests to irregular service A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. Low Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Lateral Movement, Execution
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
Analytics Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics An executable was written and executed by a web server Web server process had written an executable file that was executed shortly after. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics An identity successfully extracted multiple secrets within the organization An identity successfully dumped multiple secrets from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics Failed DNS The endpoint is performing DNS lookups that are failing at an excessively high rate when compared to its peer group. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics HTTP with suspicious characteristics Uncommon HTTP communication was performed by the host that might indicate its attempt to hide malicious activities. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Impossible traveler - SSO User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics Impossible traveler - VPN A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics Large Upload (FTP) The endpoint transferred an excessively large amounts of data to a single destination over FTP. Cortex XDR Analytics assumes endpoint traffic towards a specific destination should be about the same over long periods of time. For that reason, Cortex XDR detected this abnormal behavior of a large data upload. An attacker may be exfiltrating data directly to the internet using this protocol. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (Generic) The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics Logs were not collected from a data source for an abnormally long time Logs were not collected from a data source for an abnormally long time. Low Platform Analytics Health Monitoring Data Impact
Analytics Machine Account NTLM Relay An NTLM NTProofStr was seen from more than one source. This indicates that machine account NTLM authentication data has been relayed. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access, Lateral Movement
Analytics Microsoft 365 storage services exfiltration activity The Microsoft Graph API was used to download Microsoft OneDrive and SharePoint files. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics ML artifacts destruction An identity deleted multiple ML artifacts. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple Azure AD admin role removals An Azure AD identity removed multiple administrators from their roles. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Impact
Analytics Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. Low Identity Analytics XDR Agent Execution
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics Multiple suspicious user accounts were created A user was observed creating multiple rare user accounts. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics XDR Agent Credential Access
Analytics Multiple Weakly-Encrypted Kerberos Tickets Received A user accessed a number of services associated with user accounts in the 10 minutes leading to the alert, generating a number of weakly encrypted Kerberos TGS (ticket granting service) tickets that is significantly larger than the number of weakly encrypted TGS tickets received by that user in the 30 days leading to the alert. Services associated with user accounts are a common target for Kerberoasting due to default weak encryption. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. Low Identity Threat Detection (ITDR) Office 365 Audit Initial Access
Analytics Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics Potential kubelet impersonation attempt A process accessed both the Kubelet credentials and the Kubernetes CA certificate, indicating an attempt to impersonate the node agent and communicate with the API server. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Rare LDAP enumeration Possible LDAP enumeration with a rare combination of queries. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Discovery
Analytics Short-lived user account A user was created and deleted within a short period of time. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics Subdomain Fuzzing The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics Suspicious access to Kubernetes API with kubelet credentials A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster. Low Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Exfiltration, Collection
Analytics Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. Low Cortex Cloud AWS Audit Log, Azure Audit Log Execution
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics Suspicious EBS snapshots deletion An identity deleted multiple EBS snapshots from the project, considerably more than usual. Low Cortex Cloud AWS Audit Log Impact
Analytics Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. Low Platform Analytics XDR Agent Impact
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics Suspicious Kerberos Pre-Auth Failures by Host An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics Suspicious LDAP queries followed by shared folder access The user executed suspicious LDAP queries shortly before accessing a shared folder. This behavior may be indicative of Rubeus activity involving Kerberos ticket forgery, such as Golden Ticket or Silver Ticket attacks. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics User added to the SMS Admins local group A user was added to the SMS Admins local group. This may indicate a potential attack targeting the Microsoft Configuration Manager infrastructure. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics User collected remote shared files in an archive Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection