Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. Informational Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC Injection into rundll32.exe A process injected into an instance of rundll32.exe. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC LOLBAS executable injects into another process A signed binary, which can be abused to run code, injected code to another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Microsoft Office injects code into a process An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways. Low Platform Analytics XDR Agent Initial Access, Defense Evasion
Analytics BIOC Signed process performed an unpopular DLL injection A signed process performed an unpopular DLL injection into another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Signed process performed an unpopular injection A signed process performed an unpopular injection to another process. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer A process wrote a PE header to another process by calling the NtWriteVirtualMemoryRemote API function. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Unsigned and unpopular process performed a DLL injection An unsigned process with low popularity injected a dll into another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned and unpopular process performed an injection An unsigned process with low popularity injected code to another process. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Unsigned process injecting into a Windows system binary with no command line An attacker may be trying to avoid detection by injecting their malicious code into a legitimate Windows system binary. Medium Platform Analytics XDR Agent Defense Evasion, Privilege Escalation