Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
48 detectors match the current filters. tactic: TA0007 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Container enumeration An attacker may run a command to enumerate containers on a machine. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | DNS reconnaissance or enumeration via DNSRecon DNSRecon enables DNS reconnaissance and enumeration, and may be used by attackers to learn about targets' network infrastructure. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | Document discovery Attackers may use the find command to look for documents. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. | Informational | Platform Analytics | Dml connection | Discovery |
| BIOC | Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. | Informational | Platform Analytics | Process execution | Defense Evasion, Discovery |
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| BIOC | Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Linux network share discovery A Linux network share discovery command was executed. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network share discovery via command-line tool Attackers may use command-line tools to discover mapped shares on the host. | Low | Platform Analytics | Process execution | Discovery |
| BIOC | Password complexity enumeration Attackers may read system files containing password complexity requirements. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible Firefox browser history and bookmarks collection via command-line tool Attackers may collect history and bookmarks details by accessing the Firefox database. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | Possible Oracle enumeration via Oscanner The Oscanner Oracle framework performs enumeration of SIDs, account roles, privileges, hashes, and more. Attackers may attempt to gather this information during the reconnaissance phase. | Low | Platform Analytics | Process execution | Discovery |
| BIOC | Possible Oracle enumeration via tnscmd10g The tnscmd10g command-line utility was executed, allowing the enumeration of Oracle DBs. | Low | Platform Analytics | Process execution | Discovery |
| BIOC | Possible ping sweep Ping sweeps are useful tools that can detect which machines are up in the network and can be the step before lateral movement. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Potential Network Sniffing Network sniffing related processes were detected. | Informational | Platform Analytics | Process execution | Credential Access, Discovery |
| BIOC | PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Remote system discovery Remote system discovery using a system utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Shared resource management discovery using wmic.exe Attackers may use wmic.exe to discover shared resource management information. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. | Medium | Platform Analytics | Windows event log | Discovery |
| BIOC | SMB enumeration via command-line tool Attackers may use SMB enumeration to retrieve information about network shares, printers, and other resources. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| BIOC | Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. | Informational | Platform Analytics | File | Discovery |
| BIOC | System information discovery System information discovery using one of these bash utilities - lshw -short, uptime, uname -a. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System network configuration discovery System network configuration discovery using Linux command-line utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | System owner/user discovery System owner/user discovery using bash utilities. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | UDP protocol scanner execution The UDP Protocol Scanner performs UDP service discovery. Attackers may use it to enumerate UDP services in their target's environment. | Low | Platform Analytics | Process execution | Discovery |
| BIOC | Virtual Directory configuration access via PowerShell PowerShell was used to dump Exchange Web Service (EWS) Virtual Directories, which may indicate malicious behavior, for example, SolarStorm campaign. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Write to /etc/hosts file An attacker may add an entry to the hosts file, so they can route traffic to the added IP. | Informational | Platform Analytics | File | Discovery |