Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

258 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. Low Cortex Cloud AWS Audit Log Persistence
Analytics AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS root account activity The AWS root account has successfully performed an operation in the project. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS SecurityHub findings were modified AWS SecurityHub findings were modified. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC AWS SSM send command attempt An identity executed an AWS SSM Document. Informational Cortex Cloud AWS Audit Log Lateral Movement, Execution
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS user creation A new AWS user was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Bedrock model shared with a foreign account A bedrock model was shared with a foreign account through AWS resource access manager. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Bucket's block public access setting turned off S3 bucket block public access setting turned off. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud compute instance user data script modification The user data of a cloud compute instance was modified. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics BIOC Cloud compute volume creation attempt An attempt was made to create an EBS volume. Informational Cortex Cloud AWS Audit Log Defense Evasion, Collection
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics BIOC Cloud email sending was enabled Cloud email sending was enabled for the cloud account. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Cloud email service activity A cloud Identity performed an email service operation. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Lateral Movement
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs Execution
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. Medium Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. Medium Cortex Cloud AWS Audit Log Execution, Lateral Movement
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. Informational Cortex Cloud AWS Audit Log Collection
Analytics BIOC EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. High Cortex Cloud AWS Audit Log Persistence
Analytics BIOC EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM instance profile associations were described AWS IAM instance profile associations were described. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was created An AWS IAM instance profile was created. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy version was created A cloud identity created an AWS-managed IAM policy version. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to role An AWS IAM policy was attached to this role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role was created An IAM role was created. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics BIOC Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod Created With Sensitive Volume An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Kubernetes pod creation with host network An identity created a Kubernetes pod attached to the host network. This may indicate an adversary attempting to access services bound to localhost, sniff traffic on any interface on the host, and potentially bypass the network policy. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Privileged Pod Creation An identity created a Kubernetes pod with a privileged container. This may indicate an adversary attempting to access that host's filesystem or gain root access to the host. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics BIOC Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access