Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1565 ✕

Download CSV Show ATT&CK heatmap
  • Unusual AI Knowledge Base Modification Low Cloud 1 variation

    An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    5 Days
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Data Manipulation: Stored Data Manipulation (T1565.001)
    Required data: AWS Audit Log Gcp Audit Log
    Detector tags: Cloud AI Infrastructure Analytics
    Attacker's goals: Contaminating knowledge base, so that contextual information will be incorrect, biased or harmful.
    Investigative actions: Check the identity that modified the knowledge base. Check recent additions to the knowledge base.

    Variations

    Suspicious AI Knowledge Base Modification

    Medium overridden

    An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases, adding a new data source type. overridden