Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
208 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity created or modified a security group A cloud identity created or modified a security group. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | A cloud identity started a Cloud Shell session A cloud identity started a Cloud Shell session. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | A cloud instance was stopped A cloud compute instance was stopped. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | A cloud storage configuration was modified A cloud storage configuration was modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A container registry was created or deleted A container registry was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes Cronjob was created A Kubernetes CronJob was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes DaemonSet was created A Kubernetes DaemonSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes deployment was created A Kubernetes deployment was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes ephemeral container was created A Kubernetes ephemeral container was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics BIOC | A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes Pod was created with a sidecar container A Kubernetes Pod was created with a sidecar container. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes Pod was deleted A Kubernetes Pod was deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes ReplicaSet was created A Kubernetes ReplicaSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | A Kubernetes service account executed an unusual API call A Kubernetes service account executed an unusual API call. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics BIOC | A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes service was created or deleted A Kubernetes service was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes StatefulSet was created A Kubernetes StatefulSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Lateral Movement |
| Analytics | Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| Analytics BIOC | AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | An AWS database service master user password was changed An AWS database service master user password was changed. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Impact |
| Analytics BIOC | An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | An AWS Lambda Function was created An AWS Lambda Function was created. | Informational | Cortex Cloud | AWS Audit Log | Execution, Persistence |
| Analytics BIOC | An AWS Lambda function was modified An AWS Lambda function was modified. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS Route 53 domain was transferred to another AWS account An AWS Route 53 domain was transferred to another AWS account. | Informational | Cortex Cloud | AWS Audit Log | Resource Development |
| Analytics BIOC | An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Impact |
| Analytics BIOC | An AWS SAML provider was modified An AWS SAML provider was modified. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Defense Evasion |
| Analytics BIOC | An AWS SES identity was deleted An AWS SES identity has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An Email address was added to AWS SES An Email address was added to AWS SES. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An IAM group was created An IAM group was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity disabled bucket logging An identity disabled bucket logging. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity started an AWS SSM session An identity started an AWS SSM interactive session. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics | AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| Analytics BIOC | AWS network ACL rule deletion An AWS network ACL rule was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS principals discovery A cloud identity has enumerated principals. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS resource discovery A cloud identity has enumerated resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS root account activity The AWS root account has successfully performed an operation in the project. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics | AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS SecurityHub findings were modified AWS SecurityHub findings were modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS SES account sending settings modified AWS SES account sending settings were modified. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Execution |