Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
8 detectors match the current filters. technique: T1546 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A rare file path was added to the AppInit_DLLs registry value A rare file path was added to AppInit_DLLs registry value. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | A WMI subscriber was created A WMI subscriber was created. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Google Workspace automation was created Google Workspace automation was created. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Execution, Persistence, Exfiltration |
| Analytics BIOC | Image file execution options (IFEO) registry key set Attackers may use the Image File Execution Options Registry key to launch their executable whenever the user attempts to execute a certain executable. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Manipulation of netsh helper DLLs Registry keys Registering netsh helper DLLs is uncommon, and could be used by malware for persistence. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Scrcons.exe Rare Child Process The Windows Management Instrumentation (WMI) standard event consumer scrcons.exe executed a rare VBScript or PowerShell script. Executing a rare script can be an indication of local or remote code execution abuse by an attacker. | Informational | Platform Analytics | XDR Agent | Execution, Persistence |
| Analytics BIOC | Screensaver process executed from Users or temporary folder An executable file with a screensaver extension was executed from the Users or temp folder. This is not a common behavior for screensavers and may indicate a malicious file disguised as a screensaver in the Users or temp folder. It is recommended to further investigate the execution flow for malicious indicators. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Uncommon Managed Object Format (MOF) compiler usage The mofcomp.exe WMI MOF compiled is used to compile code into the WMI repository that in turn may enable attackers to run scheduled or triggered code from the context of a Microsoft-signed binary. | Informational | Platform Analytics | XDR Agent | Persistence |