Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

9 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Possible crypto miner was detected on a host The host produced traffic consistent with the crypto mining. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Impact
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics BIOC Correlation rule error An error was identified while running a correlation rule. Medium Platform Analytics Health Monitoring Data Impact
Analytics BIOC Error in event forwarding An error was detected in event forwarding. Medium Platform Analytics Health Monitoring Data Impact
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
BIOC Manipulation of Windows Safe Boot configuration Safe-boot Registry settings deletion. Medium Platform Analytics Registry Impact
Analytics BIOC Parsing Rule Error A Parsing Rule error was detected. Medium Platform Analytics Health Monitoring Data Impact
BIOC Process changes the Windows logon text This registry key is used to display a legal notice when logging on to the computer. This is used by the DXXD ransomware to notify the user. Medium Platform Analytics Registry Impact
Analytics BIOC Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access