Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1048 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| Analytics BIOC | First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics BIOC | Sending unusual file(s) to an external address Unusual files sent to an external address. | Low | Email Security | Microsoft 365 Emails | Initial Access, Exfiltration |
| Analytics BIOC | WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. | Informational | Platform Analytics | XDR Agent | Exfiltration |