Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

44 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A cloud storage configuration was modified A cloud storage configuration was modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An AWS SAML provider was modified An AWS SAML provider was modified. Informational Cortex Cloud AWS Audit Log Initial Access, Defense Evasion
Analytics BIOC An identity disabled bucket logging An identity disabled bucket logging. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS data asset shared public A data asset was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SecurityHub findings were modified AWS SecurityHub findings were modified. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud compute volume creation attempt An attempt was made to create an EBS volume. Informational Cortex Cloud AWS Audit Log Defense Evasion, Collection
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
Analytics BIOC MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion