Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. technique: T1566 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
BIOC Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. Informational Platform Analytics File Initial Access
BIOC Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. Informational Platform Analytics Process execution Initial Access
BIOC Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. Informational Platform Analytics File Initial Access
BIOC Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. Informational Platform Analytics Process execution Initial Access
BIOC Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. Informational Platform Analytics Process execution Initial Access
BIOC Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. Informational Platform Analytics File Initial Access