Skip to content
%
GoCortexIO Snippets
home
latest
about
rss
#alerts
18 snippets
2026-09-22 23:09 UTC
Cortex XDR
:
Spot persistence attempts by monitoring reg.exe command-line executions adding auto-start entries under Windows Run or RunOnce registry keys.
#alerts
#detection
#multi-tenant
#xql
#T1547.001
2026-09-10 23:34 UTC
Cortex XSIAM
:
Anthropic Threat Report (Sept 2026) - Multi-GTG Threat Hunt
#alerts
#detection
#multi-tenant
#xql
2026-09-07 23:46 UTC
Cortex XDR
:
Local browser credential vault harvesting (Infostealers)
#alerts
#detection
#multi-tenant
#xql
#T1555.003
2026-08-29 07:38 UTC
Cortex XDR
:
TerminalFix campaign deploys a reverse tunnel through multistage intrusion.
#agent
#alerts
#detection
#xql
#T1562.001
#T1548
#T1059
2026-08-20 00:46 UTC
Cortex XDR
:
Hunt for unauthorised deployments of legitimate, signed Remote Monitoring and Management tools being abused for hands-on-keyboard adversary activity.
#alerts
#detection
#multi-tenant
#xql
#T1219
2026-08-13 00:36 UTC
Cortex XDR
:
ShieldBreak (by Nightmare Eclipse) Hunting
#agent
#alerts
#detection
#multi-tenant
#xql
#T1562.001
#T1548
2026-08-11 02:55 UTC
Cortex XDR
:
Detect early-stage hypervisor attacks for telltale ESXi-specific commands and SSH arguments used by adversaries to prepare lateral movement into your virtualisation estate.
#alerts
#detection
#multi-tenant
#xql
#T1486
2026-08-02 23:54 UTC
Cortex XSIAM
:
Thwart anti-forensic cover-ups by detecting the intentional wiping of the NTFS USN change journal, a deliberate tactic used by adversaries to erase digital footprints and hinder incident response ...
#alerts
#detection
#multi-tenant
#xql
#T1070
2026-07-19 23:22 UTC
Cortex XDR
:
Detect critical ransomware precursors by monitoring for the abrupt destruction of Volume Shadow Copies, a definitive indicator of likely Ransomware.
#alerts
#detection
#multi-tenant
#xql
#T1490
2026-07-13 02:15 UTC
Cortex XDR
:
Hunt for adversaries abusing the Background Intelligent Transfer Service (BITS) to download malicious payloads or exfiltrate data under the radar.
#alerts
#detection
#multi-tenant
#xql
#T1197
2026-07-06 05:24 UTC
Cortex XDR
:
Hunt adversaries attempting to weaponise trusted certificate utility to pull down external payloads whilst exploiting local caching to mask their digital footprints.
#alerts
#detection
#multi-tenant
#xql
#T1105
2026-07-02 04:42 UTC
Cortex XSIAM
:
Seasons don't fear the reaper, but your Linux endpoints definitely should when RingReaper weaponizes io_uring to silently sever its system call hooks.
#T1106
#xql
#detection
#alerts
2026-06-30 04:08 UTC
Cortex XDR
:
Expose hidden internal pivot points by detecting where adversaries have manipulated the native Windows network routing configuration (portproxy) to forward malicious traffic through a compromised ...
#alerts
#detection
#multi-tenant
#xql
#T1090.001
2026-06-23 04:05 UTC
Cortex XDR
:
Hunt down and intercept attackers using the native 'Install from Media' feature to clone your Active Directory database for offline credential cracking.
#alerts
#detection
#multi-tenant
#xql
#T1003.003
2026-06-12 03:55 UTC
Cortex XDR
:
Uncover heavily obfuscated or encoded PowerShell commands designed to evade standard command-line logging and scrutiny.
#alerts
#detection
#multi-tenant
#xql
#T1059.001
2026-06-12 03:52 UTC
Cortex XDR
:
Analyse how threat actors abuse the trusted system installer to pull down external payloads, and hunt on this common initial access vector.
#alerts
#detection
#multi-tenant
#xql
#T1218.007
2026-05-29 05:11 UTC
Cortex XDR
:
Detect stealthy living-off-the-land techniques where the built-in Microsoft HTML Application host is weaponised to bypass your endpoint application control policies.
#alerts
#detection
#multi-tenant
#xql
#T1218.005
2026-05-06 08:25 UTC
Cortex XDR
:
Hunt for lateral movement indicators by identifying anomalous Windows Management Instrumentation activity that signals an attacker is executing code across your internal network.
#alerts
#detection
#xql
#T1047