Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

38 detectors match the current filters. tactic: TA0003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes Cronjob was created A Kubernetes CronJob was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS Lambda Function was created An AWS Lambda Function was created. Informational Cortex Cloud AWS Audit Log Execution, Persistence
Analytics BIOC An Email address was added to AWS SES An Email address was added to AWS SES. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An IAM group was created An IAM group was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC AWS user creation A new AWS user was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was created An AWS IAM instance profile was created. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy version was created A cloud identity created an AWS-managed IAM policy version. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to role An AWS IAM policy was attached to this role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role was created An IAM role was created. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. Informational Cortex Cloud AWS Audit Log Persistence, Credential Access, Lateral Movement
Analytics BIOC Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Lateral Movement
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion