Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

56 detectors match the current filters. tactic: TA0006 ✕ technique: T1110 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user connected from a new country A user connected from an unusual country that the user has not connected from before. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC A user connected to a VPN from a new country A user connected to a VPN from an unusual country that the user has not connected from before. This may indicate the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. Informational Identity Analytics XDR Agent Credential Access, Resource Development
Analytics A user rejected an SSO request from an unusual country A user rejected an SSO authentication request from an abnormal country. Low Identity Analytics Okta, OneLogin Credential Access, Resource Development
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
BIOC Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. Medium Platform Analytics Process execution Discovery, Credential Access
Analytics BIOC External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics BIOC First connection from a country in organization A user connected to an SSO service from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC First VPN access attempt from a country in organization A user attempted to connect from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics BIOC Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. High Platform Analytics XDR Agent Credential Access
Analytics Impossible traveler - SSO User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics Impossible traveler - VPN A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC Initial person-to-person email contact Identifies when a sender initiates contact with individuals with no prior history of interaction in the last 30 days. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Initial Access
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics XDR Agent Credential Access
Analytics IP Rotation Pattern in SSO Spray A high volume of SSO authentication attempts was observed in a short time window. This behavior may indicate a password spray attack targeting multiple accounts. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
BIOC Kerberos brute-force attack using Kerbrute This is a known Kerbrute tool command, used to conduct Kerberos authentication brute-force attacks. Informational Platform Analytics Process execution Credential Access
Analytics Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. Informational Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Credential Access
Analytics BIOC Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Possible Brute Force in universal authentication An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack. Informational Identity Analytics Credential Access, Resource Development
Analytics Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. Informational Platform Analytics XDR Agent Credential Access
Analytics Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. High Platform Analytics XDR Agent Credential Access
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
Analytics Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. Low Identity Analytics XDR Agent Credential Access
Analytics Possible Password Spray in universal authentication An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack. Informational Identity Analytics Credential Access, Resource Development
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
Analytics Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. Informational Identity Analytics XDR Agent Credential Access
Analytics SSO Brute Force An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics SSO Password Spray An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics Suspicious Kerberos Pre-Auth Failures by Host An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious sshpass command execution The sshpass command was executed, This could be an attempt to check for credential stuffing. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unusual URL(s) sent by a brand were observed in the email A URL that is not usually associated with the brand has been detected. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Usage of homograph characters detected in an email attachment(s) name Detected characters resembling Latin letters within an email attachment(s) name. This method could be used as a method to evade text or file scanners and analyzers. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC User attempted to connect from a suspicious country A user connected from an unusual country. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics VPN login Brute-Force attempt A user account failed to log in to a VPN service multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics VPN Login Password Spray An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access