Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

6 detectors match the current filters. technique: T1020 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. Informational Cortex Cloud AWS Audit Log Collection, Exfiltration
Analytics BIOC An identity accessed a backup cloud storage An identity accessed a backup cloud storage. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration