Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. technique: T1497 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Container enumeration An attacker may run a command to enumerate containers on a machine. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. | Informational | Platform Analytics | Process execution | Defense Evasion, Discovery |
| BIOC | Ping executed with loopback address This seemingly strange "wait" mechanism is often used by malware to stall command execution. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Ping to a known external IP address Pinging a known external IP address is often used by malware to check internet connectivity. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Ping to localhost from an uncommon, unsigned parent process Ping is often used by malware and attackers to delay the execution of suspicious commands in sandbox environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Security tools detection attempt A script has executed commands that can be used to detect security tools. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| BIOC | VirtualBox enumeration VBoxManage can be used to enumerate local VirtualBox machines. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | VM Detection attempt A script has executed commands that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Discovery |
| Analytics BIOC | VM Detection attempt on Linux A Process executed a command and/or accessed a file that can be used to detect VM environments. | Informational | Platform Analytics | XDR Agent | Defense Evasion, Discovery |
| BIOC | VMware enumeration attempt An attacker may check for virtualization by searching for local vmx (VMware configuration) files. | Informational | Platform Analytics | Process execution | Discovery |