Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
15 detectors match the current filters. tactic: TA0043 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A user accessed multiple time-consuming websites A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics | Abnormal RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Reconnaissance |
| Analytics | Abnormal SMB scanning activity to multiple hosts An endpoint performed a new, unfamiliar SMB scanning activity to multiple hosts on the network. | Informational | Platform Analytics | XDR Agent | Reconnaissance |
| Analytics BIOC | Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. | Informational | Platform Analytics | Palo Alto Networks Firewall threat Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email was received from an unknown sender using a disposable domain The email was received from an unknown sender using a disposable email provider, first seen in the organization in the past month. | Low | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics | Increase in Job-Related Site Visits A user has visited multiple job-related sites in the past day. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | Near-empty email from an external sender The email was sent from an external sender and contains minimal content. Near-empty emails from external sources are uncommon and may be used to bypass content-based detection or prompt user interaction without clear context. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance |
| Analytics BIOC | Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics | Subdomain Fuzzing The root domain within the network is experiencing an unusually high number of access requests to its subdomains, significantly exceeding the typical activity levels for that domain. This anomaly could suggest that someone is attempting to enumerate subdomains or uncover additional virtual hosts associated with the domain, possibly as part of a reconnaissance effort to identify vulnerable or less-secured entry points into the network. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | Suspicious access of the System Management Container A user accessed the System Management container, which may be an indication of a reconnaissance for site servers. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Reconnaissance |
| Analytics BIOC | Unusual display name in From header An email was detected with an unusual display name in the From header. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Reconnaissance |