Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

161 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Execution
Analytics BIOC A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. Medium Cortex Cloud AWS Audit Log, Azure Audit Log Exfiltration
Analytics BIOC A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. Medium Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A machine certificate was issued with a mismatch A machine certificate was issued with a mismatch between the requester and the subject. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A mail forwarding rule was configured in Google Workspace A rule was set up to forward emails outside the Google Workspace domain. Medium Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Exfiltration
Analytics A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Impact
Analytics BIOC A process was executed with a command line obfuscated by Unicode character substitution A process was executed with a command line obfuscated by Unicode character substitution. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A suspicious executable with multiple file extensions was created An executable file with multiple extensions was created. This technique is frequently used to disguise malware as user content. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Defense Evasion
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Correlation Rule Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account Medium Platform Analytics alibaba_action_trail_raw
BIOC AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. Medium Platform Analytics Process execution Defense Evasion
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. Medium Platform Analytics XDR Agent Persistence, Defense Evasion
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
Analytics BIOC Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. Medium Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. Medium Platform Analytics XDR Agent Persistence
BIOC Bypass UAC using the control.exe Registry key Control.exe is a Registry key known to be altered by attackers to allow themselves to run their malware with elevated privileges. Medium Platform Analytics Registry Privilege Escalation
BIOC Bypass UAC using the IsolatedCommand Registry value IsolatedCommand is a Registry value known to be altered by attackers to allow themselves to run their malware with elevated privileges. Medium Platform Analytics Registry Privilege Escalation
Correlation Rule Chrome - Known Malicious Site Visit Unsafe site $xdm.network.http.url was visited by $xdm.source.user.username via chrome profile $xdm.intermediate.user.username. Medium Platform Analytics google_workspace_chrome_raw
Correlation Rule Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. Medium Platform Analytics google_workspace_chrome_raw Execution
Correlation Rule Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. Medium Platform Analytics google_workspace_chrome_raw Initial Access
BIOC Clear logs - using dd and /dev/null Usage of the dd utility to clear the contents of a file using /dev/null. Medium Platform Analytics Process execution Defense Evasion
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. Medium Cortex Cloud AWS Audit Log Exfiltration
Analytics Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. Medium Cortex Cloud AWS Audit Log Execution, Lateral Movement
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC Correlation rule error An error was identified while running a correlation rule. Medium Platform Analytics Health Monitoring Data Impact
BIOC Credential dumping via fgdump.exe Attackers may use fgdump.exe to perform local credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via gsecdump.exe Attackers may use gsecdump to obtain password hashes and LSA secrets. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via pwdumpx.exe Attackers may use pwdumpx.exe to perform local or remote credential dumping. Medium Platform Analytics Process execution Credential Access
BIOC Credential dumping via wce.exe Attackers may use wce.exe (Windows Credential Editor) to obtain user credentials. Medium Platform Analytics Process execution Credential Access
BIOC Credential Vault command-line access The Credential Vault command line was used to enumerate a user's saved credentials. Medium Platform Analytics Process execution Credential Access
Correlation Rule CyberArk Failed Logins This correlation rule will trigger in an event in which 4 or more Failed Logins events occurred from a single user during a 10 minutes timeframe. Medium Platform Analytics cyberark_identity_raw
BIOC Delete Volume USN Journal with fsutil This technique is used by attackers to eliminate evidence of files created during post-exploitation activities. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC DNS reconnaissance or enumeration via DNSRecon DNSRecon enables DNS reconnaissance and enumeration, and may be used by attackers to learn about targets' network infrastructure. Medium Platform Analytics Process execution Discovery
Correlation Rule DropBox - Massive File Downloads This rule detects more than 100 downloaded files during an hour by the same user. This is a suspicious behavior which can be an indication of a data exfiltration. Medium Platform Analytics dropbox_dropbox_raw Exfiltration
BIOC Dumping lsass.exe memory for credential extraction Dumping lsass.exe memory to a file allows attackers to later extract credentials from the dumped memory. Medium Platform Analytics Process execution Credential Access
Analytics BIOC Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Error in event forwarding An error was detected in event forwarding. Medium Platform Analytics Health Monitoring Data Impact
Analytics BIOC Executable created to disk by lsass.exe Lsass.exe does not normally create executables to disk. This activity was seen as part of several exploits, like EternalBlue and DoublePulsar, used during the WannaCry attacks. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
BIOC Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. Medium Platform Analytics Process execution Discovery, Credential Access
Analytics BIOC Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. Medium Platform Analytics XDR Agent Privilege Escalation
Correlation Rule Gitlab - User Permission Changed User''s permissions have changed from Guest to Owner Medium Platform Analytics gitlab_gitlab_raw
BIOC Gost tunneling execution Possible use of Gost (tunnel written in Golang) SSH tunnel. Medium Platform Analytics Process execution Command and Control
BIOC Hash cracking using Hashcat tool Hash cracking allows attackers to collect passwords and use them later on as part of their operation. Medium Platform Analytics Process execution Credential Access
BIOC Impersonation using Rubeus tool User authentication should not be impersonated, since this is considered a malicious behavior. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC Indirect command execution using the Program Compatibility Assistant Pcalua.exe (Program Compatibility Assistant) is used for running old programs that have compatibility issues. Attackers can use pcalua.exe to indirectly execute their malicious programs. Medium Platform Analytics XDR Agent Defense Evasion
BIOC Kerberos ticket forging using Impacket ticketer Suspected execution of Impacket's ticketer.py script for forging TGT/TGS Kerberos tickets. Medium Platform Analytics Process execution Defense Evasion, Privilege Escalation
Analytics BIOC Kerberos Traffic from Non-Standard Process The endpoint had a non-standard process communicating over ports normally used by Kerberos. An attacker might be using malicious tools to move laterally. Medium Platform Analytics XDR Agent Discovery
Analytics Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics BIOC Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. Medium Platform Analytics XDR Agent Execution, Discovery
Analytics BIOC Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution, Discovery
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
Analytics BIOC LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Machine account was added to a domain admins group A machine account was added to a domain admins group. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
BIOC Manipulation of Firefox plugins and extensions via the Registry Plugins and extensions are loaded from all of these Registry keys. Medium Platform Analytics Registry Persistence
Analytics BIOC Manipulation of netsh helper DLLs Registry keys Registering netsh helper DLLs is uncommon, and could be used by malware for persistence. Medium Platform Analytics XDR Agent Persistence
BIOC Manipulation of the MonitorProcess Registry key Entries added under the Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SilentProcessExit can be used to run malicious code and help attackers gain persistence. Medium Platform Analytics Registry Persistence
BIOC Manipulation of the sticky keys file Possible login bypass attack. Medium Platform Analytics File Privilege Escalation
BIOC Manipulation of Windows Safe Boot configuration Safe-boot Registry settings deletion. Medium Platform Analytics Registry Impact
BIOC Manipulation of Winlogon 'UserInit' autostart Registry key Winlogon process uses the value specified in the UserInit key to launch login scripts etc. This key is location at HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon. Usually, UserInit key points to userinit.exe but if this key can be altered, then that EXE will also launch by Winlogon. Medium Platform Analytics Registry Persistence
BIOC Microsoft Office Equation Editor spawns a commonly abused process A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the current user is logged on with administrative user rights, an attacker could take control of the affected system. CVE-2017-11882 Microsoft Office Memory Corruption Vulnerability. Medium Platform Analytics Process execution Execution
BIOC Modification of logon scripts via Registry Windows logon scripts are stored in ``HKCU\Environment\UserInitMprLogonScript`` and trigger when a user logs in. Attackers may abuse them for persistence. Medium Platform Analytics Registry Persistence
BIOC Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. Medium Platform Analytics Registry Persistence, Lateral Movement
Analytics New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
BIOC New local user created via PowerShell command line Attackers may create new local users to persist access to machines. Medium Platform Analytics Process execution Persistence
BIOC NTLM Credential dumping via RpcPing.exe RpcPing.exe can be used to gain network NTLM hash for offline cracking. Medium Platform Analytics Process execution Credential Access
Analytics NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Parsing Rule Error A Parsing Rule error was detected. Medium Platform Analytics Health Monitoring Data Impact
BIOC Perl script connecting to network Perl scripts may be used by attackers to connect to their command-and-control infrastructure. Medium Platform Analytics Process execution Execution
Analytics BIOC Phantom DLL Loading An attacker might leverage existing processes missing module loads to load malicious code into trusted processes. Medium Platform Analytics XDR Agent Persistence
Analytics Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible code downloading from a remote host by Regsvr32 Regsvr32 may be used to fetch arbitrary code from a remote host and execute it without dropping the payload onto the disk. Known to be used for malicious purposes. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. Medium Platform Analytics XDR Agent Collection
Analytics BIOC Possible compromised machine account A Kerberos TGT for machine account has been used and does not match the hostname. Medium Platform Analytics XDR Agent Execution
BIOC Possible Firefox browser history and bookmarks collection via command-line tool Attackers may collect history and bookmarks details by accessing the Firefox database. Medium Platform Analytics Process execution Discovery
Analytics Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. Medium Identity Analytics XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Possible malicious .NET compilation started by a commonly abused process Attackers may use csc.exe to compile payloads on a compromised machine. Medium Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Possible Persistence via group policy Registry keys Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
BIOC Possible ping sweep Ping sweeps are useful tools that can detect which machines are up in the network and can be the step before lateral movement. Medium Platform Analytics Process execution Discovery
Analytics BIOC Possible RDP session hijacking using tscon.exe The executable tscon.exe can be used to hijack other sessions on the same computer. The attacker may use another user's credentials to proceed with the lateral movement or disguise the activity. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
BIOC Possible UAC bypass via Event Viewer Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process. Medium Platform Analytics Process execution Privilege Escalation
Analytics Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. Medium Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Initial Access
BIOC PowerShell downloads files via BITS This PowerShell argument is often used to run commands with malicious intent. Medium Platform Analytics Process execution Persistence
BIOC PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). Medium Platform Analytics Process execution Discovery
BIOC PowerShell reverse shell This rule looks for a PowerShell instance that is communicating over known Metasploit ports back to an attacker in cases of reverse shell. Medium Platform Analytics Network Execution
BIOC PowerShell runs with known Mimikatz arguments These PowerShell arguments are often used to run commands with malicious intent while running Mimikatz, a credential harvesting tool. Medium Platform Analytics Process execution Credential Access
Analytics BIOC PowerShell suspicious flags Abbreviated flags in PowerShell indicate malicious intent. Medium Platform Analytics XDR Agent Execution
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. Medium Platform Analytics XDR Agent Defense Evasion, Credential Access