Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. technique: T1005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Certutil pfx parsing Certutil was used to parse a pfx certificate file. | Low | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. | Informational | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon AppleScript designed to access sensitive application data was executed via the command line The AppleScript interpreter was executed with a script designed to access sensitive application data such as Telegram messages, Apple Notes, or cached data. | High | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Unusual process accessed a crypto wallet's files An unusual process has accessed files belonging to a cryptocurrency wallet. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a messaging app's files An unusual process has accessed files belonging to a messaging app. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Reconnaissance |
| Analytics BIOC | Unusual process accessed a web browser history file An unusual process has accessed a web browser history file. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Collection |
| Analytics | User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |