Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
5 detectors match the current filters. tactic: TA0002 ✕ technique: T1651 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Execution |
| Analytics BIOC | AWS SSM send command attempt An identity executed an AWS SSM Document. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement, Execution |
| Analytics BIOC | Cloud compute instance user data script modification The user data of a cloud compute instance was modified. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics | Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. | Medium | Cortex Cloud | AWS Audit Log | Execution, Lateral Movement |
| Analytics | Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |