Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
19 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Privilege Escalation |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Initial Access |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Command and Control |
| Analytics BIOC | Granting Access to an Account Azure access has been granted to an account. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Credential Access |
| Analytics | Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics | Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics BIOC | Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | Unusual cross projects activity A suspicious activity between different cloud projects. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |