Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
27 detectors match the current filters. tactic: TA0004 ✕ technique: T1548 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| BIOC | Bypass UAC using the control.exe Registry key Control.exe is a Registry key known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Bypass UAC using the IsolatedCommand Registry value IsolatedCommand is a Registry value known to be altered by attackers to allow themselves to run their malware with elevated privileges. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Bypassing Windows UAC using sysprep Attackers may use the sysprep.exe built-in Windows tools to bypass Windows UAC. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| BIOC | Command enumeration via sudo The 'sudo -l' command was executed to enumerate commands that can be executed by a user. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| BIOC | Discovery of files with setgid or setuid bits Attackers may try to locate files with setgid or setuid bits set to escalate privileges. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Fodhelper.exe UAC bypass Attackers may use Fodhelper.exe to bypass UAC (User Account Control) by having it spawn their malicious process. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. | Informational | Cortex Cloud | Gcp Audit Log | Privilege Escalation, Initial Access |
| Analytics BIOC | LOLBIN process executed with a high integrity level A process spawned a suspicious LOLBIN process with a higher/system integrity level. The LOLBIN process spawned with an uncommon command line. This may be an indication of malicious code execution to gain privileges. | Low | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | Manipulation of MMC Registry configuration Creation or modification of these Microsoft Management Console related entries can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | Registry | Privilege Escalation |
| Analytics | Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Possible Kerberos relay attack A suspicious local network login was observed, which might indicate on Kerberos relay attack. This attack can lead to privilege escalation by obtaining system privileges on the target. | Low | Platform Analytics | Windows Event Collector, XDR Agent | Privilege Escalation |
| BIOC | Possible UAC bypass via Event Viewer Eventvwr.exe normally only spawns mmc.exe. Attackers may use it for bypassing UAC (User Account Control) by having it spawn a different process. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Setuid and Setgid file bit manipulation The setuid or setgid bits were set on a file. | Low | Platform Analytics | XDR Agent | Privilege Escalation, Defense Evasion |
| BIOC | Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| Analytics BIOC | Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. | Informational | Platform Analytics | XDR Agent | Privilege Escalation |
| BIOC | UAC bypass using the changepk.exe Registry key Attackers may use the changepk.exe built-in Windows tool to bypass Windows UAC by modifying Registry keys. | Medium | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Unsigned integer Sudo privilege escalation Fixed in CVE-2019-14287, this known command line is used to exploit a bug in sudo to gain root privileges. | Medium | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| BIOC | Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | WSReset.exe UAC bypass Attackers may use WSReset.exe to bypass User Account Control (UAC). | Low | Platform Analytics | Process execution | Privilege Escalation |