Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

22 detectors match the current filters. tactic: TA0007 ✕ technique: T1018 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
BIOC Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
Analytics Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
BIOC Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. Informational Platform Analytics Process execution Discovery
BIOC Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). Informational Platform Analytics Process execution Discovery
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Possible ping sweep Ping sweeps are useful tools that can detect which machines are up in the network and can be the step before lateral movement. Medium Platform Analytics Process execution Discovery
BIOC Remote system discovery Remote system discovery using a system utility. Informational Platform Analytics Process execution Discovery
Analytics Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) net function was executed An attacker may use PowerSploit to reconnaissance the network. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. Informational Platform Analytics File Discovery