Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

16 detectors match the current filters. technique: T1580 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC IAM instance profile associations were described AWS IAM instance profile associations were described. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. Informational Cortex Cloud AWS Audit Log Discovery