Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. technique: T1018 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) net function was executed An attacker may use PowerSploit to reconnaissance the network. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts An attacker may use PowerSploit to reconnaissance the network for exposed hosts to move laterally to. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet An attacker may use one of Microsoft's Active Directory PowerShell module remote discovery cmdlet to reconnaissance the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery