Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
18 detectors match the current filters. tactic: TA0009 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Built-in SoundRecorder tool capturing audio SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Collecting audio via PowerShell command An attacker may collect audio from the microphone using PowerShell. | Low | Platform Analytics | Process execution | Collection |
| BIOC | Command-line creation of a RAR archive Compression of data into a RAR archive using the rar.exe utility. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Compressed archive created using tar Attackers may use the tar built-in tool to stage a file for exfiltration. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| BIOC | PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Screen capture via command-line tool Attackers may use the window system screen capture tool to collect screenshots. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. | Informational | Platform Analytics | File | Collection |
| BIOC | Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. | Informational | Platform Analytics | File | Collection |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | File | Credential Access, Collection |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | Process execution | Credential Access, Collection |
| BIOC | Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. | Informational | Platform Analytics | File | Collection |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |
| BIOC | Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |