Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
13 detectors match the current filters. technique: T1526 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Discovery |
| Analytics | Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics | IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics | Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics | Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery, Defense Evasion |
| Analytics BIOC | Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Lateral Movement |