Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
43 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Backup vault policy was modified A cloud identity has modified backup vault access policy. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | A cloud storage configuration was modified A cloud storage configuration was modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log | Exfiltration |
| Analytics BIOC | An AWS database service master user password was changed An AWS database service master user password was changed. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Impact |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity disabled bucket logging An identity disabled bucket logging. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown S3 bucket An RDS snapshot was exported to an S3 bucket. The destination S3 bucket was not seen in your organization in the last 30 days. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Bucket's block public access setting turned off S3 bucket block public access setting turned off. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. | Medium | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Data encryption was disabled A cloud identity has disabled data encryption. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. | Low | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics | Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration |
| Analytics BIOC | Object versioning was disabled Object versioning of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Impact |
| Analytics BIOC | S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. | High | Cortex Cloud | AWS Audit Log | Impact |