Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

258 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Backup vault policy was modified A cloud identity has modified backup vault access policy. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Execution
Analytics BIOC A cloud identity started a Cloud Shell session A cloud identity started a Cloud Shell session. Informational Cortex Cloud AWS Audit Log Execution
Analytics BIOC A cloud instance was stopped A cloud compute instance was stopped. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud storage configuration was modified A cloud storage configuration was modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. Medium Cortex Cloud AWS Audit Log, Azure Audit Log Exfiltration
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. Informational Cortex Cloud AWS Audit Log Initial Access, Credential Access
Analytics BIOC A container registry was created or deleted A container registry was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes Cronjob was created A Kubernetes CronJob was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes DaemonSet was created A Kubernetes DaemonSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes deployment was created A Kubernetes deployment was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes ephemeral container was created A Kubernetes ephemeral container was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics BIOC A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes Pod was created with a sidecar container A Kubernetes Pod was created with a sidecar container. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes Pod was deleted A Kubernetes Pod was deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes ReplicaSet was created A Kubernetes ReplicaSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics BIOC A Kubernetes service account executed an unusual API call A Kubernetes service account executed an unusual API call. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes service was created or deleted A Kubernetes service was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes StatefulSet was created A Kubernetes StatefulSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC An AWS Lambda Function was created An AWS Lambda Function was created. Informational Cortex Cloud AWS Audit Log Execution, Persistence
Analytics BIOC An AWS Lambda function was modified An AWS Lambda function was modified. Informational Cortex Cloud AWS Audit Log Execution
Analytics BIOC An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS Route 53 domain was transferred to another AWS account An AWS Route 53 domain was transferred to another AWS account. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An AWS SAML provider was modified An AWS SAML provider was modified. Informational Cortex Cloud AWS Audit Log Initial Access, Defense Evasion
Analytics BIOC An AWS SES identity was deleted An AWS SES identity has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. Informational Cortex Cloud AWS Audit Log Collection, Exfiltration
Analytics BIOC An Email address was added to AWS SES An Email address was added to AWS SES. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An IAM group was created An IAM group was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An identity accessed a backup cloud storage An identity accessed a backup cloud storage. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity disabled bucket logging An identity disabled bucket logging. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An identity started an AWS SSM session An identity started an AWS SSM interactive session. Informational Cortex Cloud AWS Audit Log Lateral Movement
Analytics An identity successfully extracted multiple secrets within the organization An identity successfully dumped multiple secrets from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported to an unknown S3 bucket An RDS snapshot was exported to an S3 bucket. The destination S3 bucket was not seen in your organization in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS data asset shared public A data asset was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. Informational Cortex Cloud AWS Audit Log Impact
Analytics AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. Low Cortex Cloud AWS Audit Log Persistence