Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

21 detectors match the current filters. technique: T1547 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC An uncommon file added to startup-related Registry keys An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon file was created in the startup folder An uncommon file was created in the startup folder. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Execution of an uncommon process at an early startup stage Uncommon execution of an executable found in an early startup stage. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process at an early startup stage by Windows system binary Uncommon execution of an executable found in an early startup stage by Windows system binary. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process with a local/domain user SID at an early startup stage Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Microsoft Office adds a value to autostart Registry key Microsoft Office adds a value to a registry entry (run keys, startup folders) to establish persistence. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Office process accessed an unusual .LNK file An attacker may embed a .LNK file in an Office document to execute malicious code. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Persistence
Analytics BIOC Possible Persistence via group policy Registry keys Group Policy registry keys were read during system startup. This behavior may indicate a persistence mechanism that triggers on reboot to execute malicious code. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Script file added to startup-related Registry keys An attacker may add a script file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Setting Windows Auto Logon by uncommon process Setting Windows Auto Logon by uncommon process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Suspicious active setup registered The endpoint registered a new active setup, which may be used to gain persistence on the host by loading libraries into the time management service. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Suspicious authentication package registered The endpoint registered a suspicious authentication package, which may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious print processor registered The endpoint registered a new print processor, which may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious RunOnce Parent Process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user login events. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious runonce.exe parent process Runonce.exe executes commands under the Registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce, typically on computer boot and user logon events. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious time provider registered The endpoint time provider has been tampered, this change may be used to gain persistence on the host by loading libraries into the time management service. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Suspicious Udev driver rule execution manipulation Udev driver rule was modified with unusual pattern, might be used by adversaries to backdoor existing drivers. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Uncommon AppleScript containing a potential persistence command was executed via the command line The AppleScript interpreter executed an uncommon command potentially used for persistence to maintain system access. Low Platform Analytics XDR Agent Execution, Persistence
Analytics BIOC Uncommon login item persistency was registered or modified An uncommon login item persistence mechanism was registered/modified on the system. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Uncommon Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation