Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. tactic: TA0007 ✕ technique: T1083 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Document discovery Attackers may use the find command to look for documents. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Possible path traversal via HTTP request The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Discovery |
| BIOC | Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |