Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. tactic: TA0009 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A mail forwarding rule was configured in Google Workspace A rule was set up to forward emails outside the Google Workspace domain. Medium Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Exfiltration
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Possible collection of screen captures with Windows Problem Steps Recorder Windows Problem Steps Recorder (psr.exe), can record screen and clicks. Adversaries may abuse psr.exe to create screen captures and collect them afterward. Medium Platform Analytics XDR Agent Collection
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Uncommon SetWindowsHookEx API invocation of a possible keylogger A process installed a Windows desktop hook by calling the SetWindowsHookEx API function with an unpopular module. This behavior is commonly seen in keyloggers. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Collection