Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC An identity disabled bucket logging An identity disabled bucket logging. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SecurityHub findings were modified AWS SecurityHub findings were modified. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion