Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. tactic: TA0004 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Installation of a new System-V service Installation of a new System-V service. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. Informational Platform Analytics XDR Agent Privilege Escalation
Analytics BIOC Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. Low Platform Analytics XDR Agent Privilege Escalation, Defense Evasion
Analytics BIOC Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Suspicious process modified RC script file A suspicious process modified an RC script file. These files allow system administrators to map and start custom services at startup for different run levels. This may be done to establish persistence. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation