Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
23 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. | Low | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access, Execution |
| Analytics BIOC | A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics | An identity successfully extracted multiple secrets within the organization An identity successfully dumped multiple secrets from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Credential Access |
| Analytics BIOC | Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Discovery |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics | Suspicious AWS SSM parameters retrieval activity An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Collection |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual key management activity A cloud identity performed a key management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual Kubernetes secret access Suspicious Kubernetes secret access. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |