Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

78 detectors match the current filters. tactic: TA0007 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics BIOC A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment A new server has been added to an Azure Active Directory Hybrid Health AD FS Environment. Informational Cortex Cloud Azure Audit Log Discovery
Analytics BIOC A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC A user changed the Windows system time A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine. Informational Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC An Azure application reached a throttling API rate An Azure application has executed a high volume of Microsoft Graph API calls, causing a throttling error. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics BIOC Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Discovery
Analytics BIOC IAM instance profile associations were described AWS IAM instance profile associations were described. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC Kerberos Traffic from Non-Standard Process The endpoint had a non-standard process communicating over ports normally used by Kerberos. An attacker might be using malicious tools to move laterally. Medium Platform Analytics XDR Agent Discovery
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. Medium Platform Analytics XDR Agent Execution, Discovery
Analytics BIOC Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution, Discovery
Analytics BIOC LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC LDAP search query from an unpopular and unsigned process An unpopular and unsigned process performed an LDAP search query. This may be indicative of LDAP enumeration. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local group enumeration via RPC A user enumerated local groups via RPC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Local user enumeration via SAMR A user enumerated local users via SAMR. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access, Discovery
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Possible GPO Enumeration A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible network service discovery via command-line tool An attacker may use command-line utilities to discover open ports and services on a remote host. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics BIOC Possible path traversal via HTTP request The endpoint received a suspicious URI via an HTTP request that resembles a path traversal attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Discovery
Analytics BIOC Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Security tools detection attempt A script has executed commands that can be used to detect security tools. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC SMB Traffic from Non-Standard Process SMB traffic is usually performed by a standard set of privileged processes through designated ports. The endpoint had a non-standard process communicating over ports normally used by SMB. An attacker might be moving laterally by using tools that implement a custom version of the SMB protocol. Low Platform Analytics XDR Agent Discovery
Analytics BIOC SUID/GUID permission discovery Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious Certutil AD CS contact A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface. Low Platform Analytics XDR Agent Discovery, Credential Access
Analytics BIOC Suspicious LDAP search query executed A suspicious and unpopular LDAP search query was executed. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerShell Enumeration of Running Processes Attackers often enumerate running processes to find and disable security tools. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) net function was executed An attacker may use PowerSploit to reconnaissance the network. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC System information discovery via psinfo.exe Using psinfo.exe, the attacker can gather information about the network, and gain an in-depth understanding of which devices are relevant to attack. Low Platform Analytics XDR Agent Discovery
Analytics BIOC System profiling WMI query execution Attackers or malware may use WMI queries to identify the system and evade execution in sandbox environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon ARP cache listing via arp.exe The arp.exe command is used to display and modify entries in the Address Resolution Protocol (ARP) cache. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon attempt at discovering a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon IP Configuration Listing via ipconfig.exe The 'ipconfig' command is used to display TCP/IP network configuration information and refresh the Dynamic Host Configuration Protocol (DHCP) and Domain Name System (DNS) settings. Adversaries may use the command to discover network configuration details. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Uncommon routing table listing via route.exe The route.exe command is used to display and modify entries in the local IP routing table. Adversaries may attempt to use the command to discover remote systems they could compromise. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Unusual access to Microsoft 365 storage services Unusual access was detected to a Microsoft 365 storage service. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. Informational Cortex Cloud AWS Audit Log Discovery, Lateral Movement
Analytics BIOC Unusual IAM enumeration activity by a non-user Identity An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity. Informational Cortex Cloud Gcp Audit Log Discovery
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics BIOC Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. Low Platform Analytics XDR Agent Discovery
Analytics BIOC Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Collection
Analytics BIOC Unusual resource access by Azure application An Azure application had interacted with an unusual resource using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery
Analytics BIOC VM Detection attempt A script has executed commands that can be used to detect VM environments. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Discovery
Analytics BIOC VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. Informational Platform Analytics XDR Agent Defense Evasion, Discovery