Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. tactic: TA0008 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. Informational Platform Analytics Process execution Lateral Movement, Execution
BIOC Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. Informational Platform Analytics File Lateral Movement
BIOC Kerberos service ticket request in PowerShell command Asking for a specific Kerberos service ticket can indicate an attacker's attempt to "Kerberoast" or use the ticket directly. High Platform Analytics Process execution Credential Access, Lateral Movement
BIOC Manipulation of RDP settings Possible modification of Terminal Services/RDP settings. Informational Platform Analytics Registry Lateral Movement
BIOC Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. Medium Platform Analytics Registry Persistence, Lateral Movement
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
BIOC RDP connections enabled via Registry by unsigned process An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Low Platform Analytics Registry Lateral Movement
BIOC RDP connections enabled via Registry from a script host or rundll32.exe An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Informational Platform Analytics Registry Lateral Movement
BIOC Remote file copy Remote copy operation of a file using rsync or scp or sftp. Informational Platform Analytics Process execution Lateral Movement
BIOC Remote RDP session enumeration via query.exe Attackers may use the built-in query.exe tool to enumerate remote sessions, using the session flag. Informational Platform Analytics Process execution Lateral Movement
BIOC Remote RDP session enumeration via qwinsta.exe Attackers may use the built-in qwinsta.exe tool to enumerate remote sessions. Informational Platform Analytics Process execution Lateral Movement