Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

34 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Backup vault policy was modified A cloud identity has modified backup vault access policy. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics An identity successfully extracted multiple secrets within the organization An identity successfully dumped multiple secrets from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC An RDS snapshot was exported to an unknown S3 bucket An RDS snapshot was exported to an S3 bucket. The destination S3 bucket was not seen in your organization in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS data asset shared public A data asset was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Bedrock model shared with a foreign account A bedrock model was shared with a foreign account through AWS resource access manager. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics ML artifacts destruction An identity deleted multiple ML artifacts. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. Low Cortex Cloud AWS Audit Log, Azure Audit Log Execution
Analytics BIOC Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics Suspicious EBS snapshots deletion An identity deleted multiple EBS snapshots from the project, considerably more than usual. Low Cortex Cloud AWS Audit Log Impact
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. Low Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics BIOC Unusual AI dataset modification A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI Knowledge Base Modification An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI RAG Knowledge Base Modification AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual cross projects activity A suspicious activity between different cloud projects. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access