Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

63 detectors match the current filters. technique: T1021 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A remote service was created via RPC over SMB A remote service was created via RPC over SMB. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
Analytics A user established an SMB connection to multiple hosts A user established an SMB connection to multiple hosts. This might indicate an enumeration attempt by a compromised account. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An identity started an AWS SSM session An identity started an AWS SSM interactive session. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC An uncommon executable was remotely written over SMB to an uncommon destination An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC AWS SSM send command attempt An identity executed an AWS SSM Document. Informational Cortex Cloud AWS Audit Log Lateral Movement, Execution
Analytics BIOC Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. Informational Cortex Cloud Azure Audit Log Defense Evasion, Lateral Movement
Analytics BIOC Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. Informational Cortex Cloud Azure Audit Log Execution, Lateral Movement
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. Medium Cortex Cloud AWS Audit Log Execution, Lateral Movement
BIOC Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. Informational Platform Analytics Process execution Lateral Movement, Execution
Analytics BIOC DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
BIOC Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. Informational Platform Analytics File Lateral Movement
BIOC Manipulation of RDP settings Possible modification of Terminal Services/RDP settings. Informational Platform Analytics Registry Lateral Movement
Analytics Multiple alerts associated with a single RDP connection Multiple alerts associated with a single RDP connection were triggered. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Lateral Movement
BIOC Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. Medium Platform Analytics Registry Persistence, Lateral Movement
Analytics New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. Medium Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. Informational Identity Analytics XDR Agent Credential Access, Lateral Movement
BIOC PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. Informational Platform Analytics Network Lateral Movement, Execution
BIOC PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. Informational Platform Analytics Registry Lateral Movement, Execution
Analytics BIOC Rare DCOM RPC activity The endpoint performed abnormal DCOM RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare file transfer over SMB protocol The endpoint performed an abnormal file transfer over SMB to a remote host. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare process with VNC server capabilities started A rare process with VNC server capabilities was started. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Rare RDP session to a remote host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare Remote Service (SVCCTL) RPC activity The endpoint performed abnormal RPC activity via Service Control Manager interface to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics BIOC Rare Scheduled Task RPC activity The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare Scheduled Task RPC activity from a rarely seen host The endpoint performed abnormal Scheduled Task RPC activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Persistence
Analytics BIOC Rare SMB session to a remote host The endpoint performed a rare SMB activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Rare SSH Session Secure Shell (SSH) provides a secure means of remote administration. Attackers can use valid SSH credentials and keys to remotely connect to endpoints running the SSH service. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Rare Windows Remote Management (WinRM) HTTP Activity The endpoint performed unfamiliar WinRM HTTP activity to a remote host. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Lateral Movement
Analytics BIOC Rare WinRM Session Windows Remote Management (WinRM) enables users to interact with remote systems in different ways, including running executables on the remote system. WinRM sessions can be established using WinRM/WinRS commands or programs such as PowerShell. Attackers can use WinRM to execute code and move laterally within a compromised network. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC RDP Connection to localhost An RDP connection to localhost can be used for privilege escalation by leveraging Windows accessibility features. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC RDP connections enabled remotely via Registry An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
BIOC RDP connections enabled via Registry by unsigned process An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Low Platform Analytics Registry Lateral Movement
BIOC RDP connections enabled via Registry from a script host or rundll32.exe An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. Informational Platform Analytics Registry Lateral Movement
Analytics BIOC RDP from an unmanaged endpoint in a typically managed subnet An RDP connection was established from an unmanaged endpoint in a typically managed subnet, indicating a possible lateral movement. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Lateral Movement
Analytics BIOC Remote DCOM command execution A remotely triggered DCOM initiated a command execution by a host that rarely executes processes using DCOM to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Remote PsExec-like command execution A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts. Informational Platform Analytics XDR Agent Lateral Movement, Execution
BIOC Remote RDP session enumeration via query.exe Attackers may use the built-in query.exe tool to enumerate remote sessions, using the session flag. Informational Platform Analytics Process execution Lateral Movement
BIOC Remote RDP session enumeration via qwinsta.exe Attackers may use the built-in qwinsta.exe tool to enumerate remote sessions. Informational Platform Analytics Process execution Lateral Movement
Analytics BIOC Remote service command execution from an uncommon source A remotely triggered service initiated a command execution by a host that rarely triggers services to other remote hosts. High Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote service start from an uncommon source A remotely triggered service initiated by a host that rarely triggers services to other remote hosts. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Remote WMI process execution A host that rarely initiates WMI to other remote hosts triggered a remote process execution by using WMI RPC. Medium Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics BIOC Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Lateral Movement
Analytics BIOC Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Lateral Movement, Defense Evasion
Analytics BIOC Uncommon Linux remote shell command execution An unusual process execution of a shell command on Linux from a remote source. This action may indicate possible exploitation or shell command execution via a backdoor. Informational Platform Analytics XDR Agent Execution, Lateral Movement
Analytics BIOC Uncommon RDP connection RDP is used by attackers to laterally move to new hosts. Standard processes do not usually implement RDP on their own, and attackers might inject or tunnel using a non-standard process. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Uncommon VNC server communication Uncommon VNC server network traffic was observed. Low Platform Analytics XDR Agent Command and Control, Lateral Movement
Analytics BIOC Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. Informational Cortex Cloud AWS Audit Log Discovery, Lateral Movement
Analytics BIOC Unusual internal access to network device management interface Unusual internal access to Palo Alto Networks device on management port. Informational Platform Analytics XDR Agent Lateral Movement, Discovery
Analytics BIOC WmiPrvSe.exe Rare Child Command Line A remote WMI command executed a binary proxy, the Windows Management Instrumentation (WMI) Provider Host wmiprvse.exe, which executed a rare child command line. Executing a rare child process can be an indication of remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Wsmprovhost.exe Rare Child Process The PowerShell host wsmprovhost.exe is a proxy process executed remotely through PowerShell when using Windows Remote Management (WinRM). It has executed a rare child process, which may indicate remote code execution abuse by an attacker. Low Platform Analytics XDR Agent Lateral Movement, Execution