Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. tactic: TA0011 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Base64 encoding used Attackers may use the base64 built-in binary to encode data into base64. | Informational | Platform Analytics | Process execution | Command and Control |
| BIOC | Direct access to free online DNS servers Online DNS servers are often used to bypass the company's internal DNS servers and evade detection. | Informational | Platform Analytics | Network | Command and Control |
| BIOC | DNS resolution to the Palo Alto Networks sinkhole DNS resolution to the Palo Alto Networks sinkhole. | Informational | Platform Analytics | Network | Command and Control |
| BIOC | Exchange process writing aspx files An exchange process is writing to .aspx files. This may be an actor dropping web shells. | High | Platform Analytics | File | Initial Access, Command and Control |
| BIOC | Gost tunneling execution Possible use of Gost (tunnel written in Golang) SSH tunnel. | Medium | Platform Analytics | Process execution | Command and Control |
| BIOC | Non-browser process downloads content from GitHub Check for possible attempts to use GitHub as a malicious payload deployment mechanism. This technique is known to be used frequently by threat actors to serve malicious scripts/payloads. | Informational | Platform Analytics | Network | Command and Control |
| BIOC | Plink/SSH reverse tunnel PuTTY link (Plink) / SSH can be used to create encrypted tunnels to communicate back to an attacker's C2 server. | Low | Platform Analytics | Process execution | Command and Control |
| BIOC | Socat/Netcat connects to TOR domain Unlikely behavior in standard systems. | Medium | Platform Analytics | Network | Command and Control |
| BIOC | SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. | High | Platform Analytics | Module | Initial Access, Command and Control |
| BIOC | Suspicious lock screen image file written to disk Desktopimgdownldr.exe is a built-in Windows tool used to set a lock screen or desktop background image as part of Personalization CSP. Adversaries may use it maliciously to download malware. | Low | Platform Analytics | File | Command and Control |