Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Commonly abused process executes by a remote host using PsExec This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec. | Informational | Platform Analytics | Process execution | Lateral Movement, Execution |
| BIOC | Executable copied to remote host via admin share An executable file was written to a remote host's shared system folder (such as c:\ or c:\windows) from an unsigned CGO process. | Informational | Platform Analytics | File | Lateral Movement |
| BIOC | Manipulation of RDP settings Possible modification of Terminal Services/RDP settings. | Informational | Platform Analytics | Registry | Lateral Movement |
| BIOC | Multiple RDP sessions enabled via Registry Attackers may allow multiple RDP sessions, so they could access the machine at the same time the user does. | Medium | Platform Analytics | Registry | Persistence, Lateral Movement |
| BIOC | PsExec attempts to execute a command on a remote host PsExec is a SysInternals tool used to execute commands on remote hosts. | Informational | Platform Analytics | Network | Lateral Movement, Execution |
| BIOC | PsExec execution EulaAccepted flag added to the Registry PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually. | Informational | Platform Analytics | Registry | Lateral Movement, Execution |
| BIOC | RDP connections enabled via Registry by unsigned process An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Low | Platform Analytics | Registry | Lateral Movement |
| BIOC | RDP connections enabled via Registry from a script host or rundll32.exe An attacker may enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. | Informational | Platform Analytics | Registry | Lateral Movement |
| BIOC | Remote RDP session enumeration via query.exe Attackers may use the built-in query.exe tool to enumerate remote sessions, using the session flag. | Informational | Platform Analytics | Process execution | Lateral Movement |
| BIOC | Remote RDP session enumeration via qwinsta.exe Attackers may use the built-in qwinsta.exe tool to enumerate remote sessions. | Informational | Platform Analytics | Process execution | Lateral Movement |