Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

62 detectors match the current filters. tactic: TA0011 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A commonly abused process connected to a rare cloud resource A commonly abused process connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A commonly abused process connected to a rare external host A commonly abused process connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC A non-browser process accessed a website UI An uncommon network communication between a non-browser process and a website UI. Informational Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC A process connected to a rare cloud resource A process connected to a rare cloud resource. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC A process connected to a rare external host A process connected to an external host name or directly to an IP address, which is rarely connected to from the organization. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A process connected to rare external host A process connected to a rare external host. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. High Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Command and Control
Analytics BIOC A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. High Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access, Command and Control
Analytics BIOC Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal process connection to default Meterpreter port This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC An app was added to Google Marketplace An app was added to the Google Workspace Marketplace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Command and Control
Analytics BIOC An Azure DNS Zone was modified An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration. Informational Cortex Cloud Azure Audit Log Command and Control
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC File transfer from unusual IP using known tools An adversary might use known tools to transfer tools/payloads into the compromised machine. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address by a common process (sha256) A process with a common sha256 connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon IP address connection from a signed process A signed process connected to an external IP address that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon root domain from a signed process A signed process connected to an external domain that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC Globally uncommon root-domain port combination by a common process (sha256) A process with a common sha256 connected to an external domain in a specific port that, on a global level, it usually doesn't connect to. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Globally uncommon root-domain port combination from a signed process A signed process connected to an external domain on a specific port that, on a global level, it usually doesn't connect to. Low Platform Analytics XDR Agent Defense Evasion, Command and Control
Analytics BIOC MpCmdRun.exe was used to download files into the system Attackers might be using legitimate Windows Defender executables to download malicious code onto the system. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. High Platform Analytics XDR Agent Command and Control
Analytics BIOC Non-browser access to a pastebin-like site Non-browser access to a pastebin-like site. Low Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC Rare AppID usage to a rare destination Rare AppID with port usage to rare destination. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare binary connected to a rare cloud resource Rare binary connected to a rare cloud resource. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare binary connected to a rare external host Rare binary connected to a rare external host. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare communication over email ports to external email server by unsigned process These methods are used by malware and attackers to leak data and remain undetected. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol A process made a connection to an external IP address or host that is rarely connected to by the organization. Informational Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon cloud resource A rare process created an SSH session to an uncommon cloud resource. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process created an SSH session to an uncommon external host Rare process created an SSH session to an uncommon external host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring access to rare IP The endpoint is periodically accessing an external fixed-IP address that its peers rarely use. Access to this external IP address has occurred repeatedly over many days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Recurring rare domain access from an unsigned process An unsigned process is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Recurring rare domain access to dynamic DNS domain The endpoint is periodically connecting to an external domain that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Scripting engine connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Low Platform Analytics XDR Agent Command and Control, Execution
Analytics BIOC Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. High Cortex Cloud AWS Audit Log, Gcp Audit Log Command and Control
Analytics BIOC Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Command and Control, Initial Access
Analytics BIOC Suspicious certutil command line An attacker may use certutil to download malware. Medium Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious curl user agent Suspicious user agent provided to curl command. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Suspicious ICMP packet An ICMP router advertisement was sent by a host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration
Analytics BIOC Suspicious process accessed a site masquerading as Google A suspicious process accessed a site masquerading as Google. Informational Platform Analytics XDR Agent Command and Control, Defense Evasion
Analytics BIOC Suspicious proxy environment variable setting Suspicious proxy environment variable change or definition with a rare command line. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. High Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Command and Control
Analytics BIOC Uncommon communication to an instant messaging server A rare communication between a process to a known instant messaging server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon file access over WebDAV Uncommon file access over WebDAV. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Command and Control
Analytics BIOC Uncommon Linux process communication to a rare external host An uncommon process is connecting to an external domain that is rarely accessed within the organization. This connection pattern is consistent with malware initiating connection to its command and control server. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon macOS process communication to a rare external host An uncommon process is connecting to an external host that is rarely accessed within the organization. This connection pattern is consistent with malicious activity such as command and control execution, malware download and so on. Informational Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon network tunnel creation An uncommon network tunnel was established. Informational Platform Analytics Palo Alto Networks Url Logs Command and Control
Analytics BIOC Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC Uncommon remote monitoring and management tool An uncommon Remote Monitoring and Management (RMM) product was observed. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon reverse SSH tunnel to external domain/ip An uncommon reverse SSH tunnel might have been created. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Uncommon SSH session was established An uncommon SSH session was established. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Unusual Netsh PortProxy rule Attackers may use Netsh PortProxy rules as part of malicious actions performed in an organizational network (e.g., for tunneling). Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Command and Control
Analytics BIOC Unusual SSH activity that resembles SSH proxy A host initiated and received an unusual SSH connection, which is consistent with being an SSH proxy. This behavior may indicate an attempt to establish covert command and control communication or to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control
Analytics BIOC Windows LOLBIN executable connected to a rare external host Scripts connecting to external IP addresses may be sanctioned IT scripts. However, when those external IP addresses are only receiving connections from a few specific endpoints in the organization, these scripts may be an indicator of more suspicious activity. Security testers and adversaries use offensive frameworks that employ forms of scripting which result in this type of network activity. Medium Platform Analytics XDR Agent Command and Control