Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. tactic: TA0003 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An uncommon service was started An uncommon service was started using systemctl or service processes. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation |
| Analytics BIOC | Installation of a new System-V service Installation of a new System-V service. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics BIOC | Suspicious process modified RC script file A suspicious process modified an RC script file. These files allow system administrators to map and start custom services at startup for different run levels. This may be done to establish persistence. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. | Low | Platform Analytics | XDR Agent | Persistence |