Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

4 detectors match the current filters. technique: T1055 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Injection into ping.exe A process injected into an instance of ping.exe. Informational Platform Analytics Remote code Defense Evasion
BIOC Notepad process makes a network connection Notepad.exe processes should not normally make network connections (with the occasional exception of printing documents). This can be a possible indicator of exploitation, e.g. Metasploit Meterpreter injection. Low Platform Analytics Network Defense Evasion
BIOC Unsigned process injects code into a process An unsigned process injected code into a process. This can be done to leverage a legitimate running process for an attack. Informational Platform Analytics Remote code Defense Evasion
BIOC Usage of tracing tool An attacker may be trying to use a known tracing tool to gather information from other processes. Informational Platform Analytics Process execution Defense Evasion