Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. tactic: TA0040 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Impact |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics BIOC | Correlation rule error An error was identified while running a correlation rule. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Error in event forwarding An error was detected in event forwarding. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. | Medium | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Defense Evasion |
| BIOC | Manipulation of Windows Safe Boot configuration Safe-boot Registry settings deletion. | Medium | Platform Analytics | Registry | Impact |
| Analytics BIOC | Parsing Rule Error A Parsing Rule error was detected. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Process changes the Windows logon text This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user. | Medium | Platform Analytics | Registry | Impact |
| Analytics BIOC | Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |