
Lucas Pinho
@lucaslapinhoCompletionist
0 followers9 downloads111 copies0 likes282 views
62 detections
Filters
Last updated
All Time
Detection languages
61
1
Categories
18
16
6
6
5
Platforms
20
11
9
8
7
Products / Services
11
10
7
5
5
MITRE Techniques
12
12
11
10
9
Detects sign-in activity within Microsoft Entra ID characterized by User-Agent strings indicative of automated tools, command-line HTTP clients, and security testing software. This rule is designed for anomaly detection and necessitates correlation with other context such as source IP, authentication results, and user behavior to identify potential malicious activity.
Windows Multiple User Accounts Disabled
Cortex XDR
Detects five or more distinct Windows user-account disable events (Event ID 4725) performed by the same actor on the same host within a one-hour time bucket, which may indicate unauthorized account access removal.
Linux Unexpected Process Spawning su
Cortex XDR
Detects instances where a non-root user process launches 'su' or a shell command executing 'su' from an unusual parent process (excluding standard shells like bash/sh/zsh/ksh or elevation tools like sudo/su). This is used to identify suspicious attempts to switch user context or escalate privileges.
FortiGate Allowed RDP Connection
Cortex XDR
Detects network traffic identified by FortiGate as Remote Desktop Protocol (RDP) that has been explicitly permitted (Accept action) by the firewall policy. This rule monitors for successful packet flow through the firewall, providing visibility into potential lateral movement paths via RDP.
Detects completed administrative actions within the Cortex management console that result in a pause of endpoint protection. This action reduces security coverage on the targeted host and requires validation to ensure it aligns with authorized maintenance, troubleshooting, or incident response activities.
Detects the creation of a new role-based access control (RBAC) role within the Cortex management plane. This activity is significant as new roles can define access to sensitive administrative and security capabilities and should be reviewed to ensure alignment with least-privilege principles and authorized access-management requirements.
Detects Microsoft Entra ID Protection risk telemetry for sign-ins with unfamiliar properties. Microsoft evaluates characteristics such as ASN, browser, device, and location against the user's historical behavior to identify anomalous sign-ins that may warrant investigation.
Windows PowerShell Password Input Window
Cortex XDR
Detects a user-session window titled 'Password Input' associated with PowerShell, PowerShell Core, or PowerShell ISE processes. This technique may be used for GUI-based credential capture or social engineering.
Detects the creation of a new Group Policy Object (GPO) in Active Directory by monitoring Windows Security Event ID 5137 where the object class is 'groupPolicyContainer'. While typically an administrative task, the creation of new GPOs can be a precursor to malicious configuration changes or domain persistence via Group Policy modification.
Windows Multiple User Account Deletions
Cortex XDR
Detects five or more distinct Windows user-account deletion events (Event ID 4726) performed by the same actor on the same host within a one-hour time window, which may indicate unauthorized account access removal or malicious impact activity.
Page 2 of 7
