Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. tactic: TA0011 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Gost tunneling execution Possible use of Gost (tunnel written in Golang) SSH tunnel. Medium Platform Analytics Process execution Command and Control
Analytics Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. Medium Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
BIOC Socat/Netcat connects to TOR domain Unlikely behavior in standard systems. Medium Platform Analytics Network Command and Control
Analytics BIOC Suspicious certutil command line An attacker may use certutil to download malware. Medium Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration
Analytics BIOC Windows LOLBIN executable connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Medium Platform Analytics XDR Agent Command and Control