Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
26 detectors match the current filters. tactic: TA0004 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A contained executable from a mounted share initiated a suspicious outbound network connection A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. | Medium | Platform Analytics | XDR Agent | Privilege Escalation, Persistence |
| Analytics | A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | A machine certificate was issued with a mismatch A machine certificate was issued with a mismatch between the requester and the subject. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| BIOC | Bypass UAC using the control.exe Registry key Control.exe is a Registry key known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Bypass UAC using the IsolatedCommand Registry value IsolatedCommand is a Registry value known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| Analytics BIOC | Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | Kerberos ticket forging using Impacket ticketer Suspected execution of Impacket's ticketer.py script for forging TGT/TGS Kerberos tickets. | Medium | Platform Analytics | Process execution | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Machine account was added to a domain admins group A machine account was added to a domain admins group. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| BIOC | Manipulation of the sticky keys file Possible login bypass attack. | Medium | Platform Analytics | File | Privilege Escalation |
| BIOC | Possible UAC bypass via Event Viewer Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics | Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Suspicious dNSHostName attribute change to DC name The dNSHostName attribute of a machine account was changed to a Domain Controller server name. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| BIOC | Suspicious printer port creation via Registry An attacker may create a print job that prints to a file, overwriting any file on the OS (CVE-2020-1048). | Medium | Platform Analytics | Registry | Privilege Escalation, Persistence |
| Analytics BIOC | TGT request with a spoofed sAMAccountName - Event log A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | XDR Agent | Privilege Escalation, Persistence |
| Analytics BIOC | The CA policy EditFlags was queried The CA policy EditFlags was queried. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | UAC bypass using the changepk.exe Registry key Attackers may use the changepk.exe built-in Windows tool to bypass Windows UAC by modifying Registry keys. | Medium | Platform Analytics | Registry | Privilege Escalation |
| Analytics BIOC | Uncommon DLL-sideloading from a logical CD-ROM (ISO) device A DLL was loaded by an executable from the same folder on a logical CD-ROM device (ISO). | Medium | Platform Analytics | XDR Agent | Execution, Defense Evasion, Privilege Escalation |
| BIOC | Unsigned integer Sudo privilege escalation Fixed in CVE-2019-14287, this known command line is used to exploit a bug in sudo to gain root privileges. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Windows Installer exploitation for local privilege escalation The Windows installer (msiexec.exe) was likely exploited to run a malicious rollback script (.rbs file) instead of the original. Users should not be able to modify config.msi during the installation process, only SYSTEM should have access to it. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | WptsExtensions.dll created to disk The Task Scheduler service attempts to load the missing WptsExtensions.dll. As a result, the creation of this file may be indicative of DLL hijacking. | Medium | Platform Analytics | File | Privilege Escalation |