Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. technique: T1566 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. | Informational | Platform Analytics | Process execution | Initial Access |
| BIOC | Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. | Informational | Platform Analytics | File | Initial Access |