Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. tactic: TA0001 ✕ technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Initial Access |
| Analytics BIOC | Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. | Low | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| Analytics BIOC | Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion, Execution |