Skip to content
%
GoCortexIO Snippets
latest
snippets
about
rss
#xql
11 snippets
2026-07-19 23:22 UTC
Cortex XDR
:
Detect critical ransomware precursors by monitoring for the abrupt destruction of Volume Shadow Copies, a definitive indicator of likely Ransomware.
#alerts
#detection
#multi-tenant
#xql
#T1490
2026-07-13 02:15 UTC
Cortex XDR
:
Hunt for adversaries abusing the Background Intelligent Transfer Service (BITS) to download malicious payloads or exfiltrate data under the radar.
#alerts
#detection
#multi-tenant
#xql
#T1197
2026-07-06 05:24 UTC
Cortex XDR
:
Hunt adversaries attempting to weaponise trusted certificate utility to pull down external payloads whilst exploiting local caching to mask their digital footprints.
#alerts
#detection
#multi-tenant
#xql
#T1105
2026-07-02 04:42 UTC
Cortex XSIAM
:
Seasons don't fear the reaper, but your Linux endpoints definitely should when RingReaper weaponizes io_uring to silently sever its system call hooks.
#T1106
#xql
#detection
#alerts
2026-06-30 04:08 UTC
Cortex XDR
:
Expose hidden internal pivot points by detecting where adversaries have manipulated the native Windows network routing configuration (portproxy) to forward malicious traffic through a compromised ...
#alerts
#detection
#multi-tenant
#xql
#T1090.001
2026-06-23 04:05 UTC
Cortex XDR
:
Hunt down and intercept attackers using the native 'Install from Media' feature to clone your Active Directory database for offline credential cracking.
#alerts
#detection
#multi-tenant
#xql
#T1003.003
2026-06-12 03:55 UTC
Cortex XDR
:
Uncover heavily obfuscated or encoded PowerShell commands designed to evade standard command-line logging and scrutiny.
#alerts
#detection
#multi-tenant
#xql
#T1059.001
2026-06-12 03:52 UTC
Cortex XDR
:
Analyse how threat actors abuse the trusted system installer to pull down external payloads, and hunt on this common initial access vector.
#alerts
#detection
#multi-tenant
#xql
#T1218.007
2026-06-08 03:55 UTC
Cortex XDR
:
Hunt for compromised system binaries attempting to fetch and execute untrusted, externally hosted dynamic link libraries via rundll32.
#detection
#multi-tenant
#xql
#T1218.011
2026-05-29 05:11 UTC
Cortex XDR
:
Detect stealthy living-off-the-land techniques where the built-in Microsoft HTML Application host is weaponised to bypass your endpoint application control policies.
#alerts
#detection
#multi-tenant
#xql
#T1218.005
2026-05-06 08:25 UTC
Cortex XDR
:
Hunt for lateral movement indicators by identifying anomalous Windows Management Instrumentation activity that signals an attacker is executing code across your internal network.
#alerts
#detection
#xql
#T1047