Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

3 detectors match the current filters. tactic: TA0007 ✕ technique: T1087 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
BIOC PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). Medium Platform Analytics Process execution Discovery
BIOC SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. Medium Platform Analytics Windows event log Discovery