Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. tactic: TA0003 ✕ technique: T1505 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | An executable was written and executed by a web server Web server process had written an executable file that was executed shortly after. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Executable or Script file written by a web server process An uncommon executable or script file was created, written, or renamed by a web server process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| BIOC | Possible web shell command execution Possible command execution via a web shell for reconnaissance. | Informational | Platform Analytics | Process execution | Persistence |
| Analytics BIOC | Possible webshell file written by a web server process An uncommon file with a web file extension was created, written or renamed by a web server process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| BIOC | Potential web shell installation A web-app script file was installed on a web server. This can indicate an installation of web shell. | Informational | Platform Analytics | File | Persistence |
| Analytics BIOC | Suspicious HTTP parameters detected The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access, Persistence |
| Analytics BIOC | Uncommon jsp file write by a Java process An uncommon jsp file was written by a Java process. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | Web server CGO executed a process following a potential Webshell dropped A process was executed by a web server CGO following a potential drop of a webshell file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |