Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
28 detectors match the current filters. tactic: TA0010 ✕ technique: T1048 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| BIOC | Bitsadmin.exe used to upload data Some attacks are known to abuse BITSAdmin to hide how data upload using legitimate Windows tools. | High | Platform Analytics | Process execution | Exfiltration, Defense Evasion |
| BIOC | BitTorrent P2P file sharing The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information. | Informational | Platform Analytics | Dml connection | Exfiltration |
| BIOC | Curl connects to an external network Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics | DNS Tunneling 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. The endpoint may be remotely controlled by an attacker, and/or an attacker may have exfiltrated data from it. This detector is not supported when networking events arrive solely from Cortex XDR Linux agents. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| BIOC | FTP/SSH client reads office files Seeing FTP/SSH related software accessing office files could be an indication of data exfiltration. | Low | Platform Analytics | File | Exfiltration |
| Analytics | Large Upload (FTP) The endpoint transferred an excessively large amounts of data to a single destination over FTP. Cortex XDR Analytics assumes endpoint traffic towards a specific destination should be about the same over long periods of time. For that reason, Cortex XDR detected this abnormal behavior of a large data upload. An attacker may be exfiltrating data directly to the internet using this protocol. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration |
| Analytics | Large Upload (Generic) The endpoint transferred large amounts of data to an external site using a different protocol from HTTP/s, FTP, or SMTP. (A specific detector is used for each of those protocols.) Cortex XDR Analytics assumes that data transfers out of your network are ordinarily performed using one of those three services, so it expects that data transfers over all other ports to be low. For the same reason, Cortex XDR Analytics also assumes endpoint traffic towards a specific destination should be about the same over long periods of time. An attacker may be exfiltrating data directly to the internet. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration |
| Analytics | Large Upload (HTTPS) The endpoint transferred an excessive amount of data to an external site over HTTPS. The destination is not a popular upload site for endpoints on your network, and the endpoint performing the upload has not previously downloaded a large amount of data from the site. The upload is considered excessive based on comparison to baseline measurements of HTTPS data transfers on your network. An attacker may be exfiltrating data directly to the internet. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics | Large Upload (SMTP) The endpoint, which is not an internal SMTP server, emailed an excessive amount of data from your network. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| BIOC | Microsoft Office spawns curl/wget on a macOS device Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device. | Informational | Platform Analytics | Process execution | Exfiltration |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| BIOC | Scripting engine makes connections over DNS ports Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics BIOC | Sending unusual file(s) to an external address Unusual files sent to an external address. | Low | Email Security | Microsoft 365 Emails | Initial Access, Exfiltration |
| Analytics | Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Exfiltration |
| BIOC | Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics | Unusual attachment volume in outbound emails Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| Analytics BIOC | WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| BIOC | Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. | Informational | Platform Analytics | Network | Exfiltration |