Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

30 detectors match the current filters. tactic: TA0005 ✕ technique: T1562 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An identity disabled bucket logging An identity disabled bucket logging. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS data asset shared public A data asset was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
Analytics BIOC MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion