Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

45 detectors match the current filters. technique: T1087 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment A new server has been added to an Azure Active Directory Hybrid Health AD FS Environment. Informational Cortex Cloud Azure Audit Log Discovery
Analytics A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
BIOC Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
Analytics IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics BIOC LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC LDAP search query from an unpopular and unsigned process An unpopular and unsigned process performed an LDAP search query. This may be indicative of LDAP enumeration. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Local user enumeration via SAMR A user enumerated local users via SAMR. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Possible Oracle enumeration via Oscanner The Oscanner Oracle framework performs enumeration of SIDs, account roles, privileges, hashes, and more. Attackers may attempt to gather this information during the reconnaissance phase. Low Platform Analytics Process execution Discovery
Analytics BIOC Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. Informational Platform Analytics Process execution Discovery
BIOC Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. Informational Platform Analytics Process execution Discovery
BIOC PowerShell dumps users and roles from Exchange server PowerShell is used to dump users and roles from Exchange servers, this may indicate malicious behavior (e.g. the SolarStorm campaign). Medium Platform Analytics Process execution Discovery
Analytics Rare LDAP enumeration Possible LDAP enumeration with a rare combination of queries. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Discovery
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
BIOC SharpHound LDAP query SharpHound is a BloodHound ingestor that performs LDAP queries to enumerate Active Directory. Medium Platform Analytics Windows event log Discovery
BIOC Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. Informational Platform Analytics Process execution Discovery, Privilege Escalation
BIOC Suspicious access to /etc/shadow Attackers may enumerate or modify user accounts by accessing the /etc/shadow file. Informational Platform Analytics File Discovery
Analytics BIOC Suspicious LDAP search query executed A suspicious and unpopular LDAP search query was executed. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Uncommon access to /etc/passwd A process made an uncommon attempt to access /etc/passwd. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. Informational Platform Analytics XDR Agent Discovery, Persistence
Analytics BIOC Unusual IAM enumeration activity by a non-user Identity An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity. Informational Cortex Cloud Gcp Audit Log Discovery
Analytics Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. Informational Cortex Cloud AWS Audit Log Discovery
Analytics User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC User discovery via WMI query execution Attackers or malware may use WMI queries to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Discovery