Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
28 detectors match the current filters. technique: T1098 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Lateral Movement |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Cloud access key creation Cloud access key creation by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was created An AWS IAM instance profile was created. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy version was created A cloud identity created an AWS-managed IAM policy version. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to role An AWS IAM policy was attached to this role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM User added to an IAM group An IAM user was added to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Lateral Movement |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |