Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

20 detectors match the current filters. tactic: TA0004 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. Informational Cortex Cloud Azure Audit Log Initial Access, Privilege Escalation
Analytics BIOC An Azure Kubernetes Role or Cluster-Role was modified An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted. This could indicate a security breach or malicious activity. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC External user invitation to Azure tenant An external user was invited to Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod Created With Sensitive Volume An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes pod creation with host network An identity created a Kubernetes pod attached to the host network. This may indicate an adversary attempting to access services bound to localhost, sniff traffic on any interface on the host, and potentially bypass the network policy. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Privileged Pod Creation An identity created a Kubernetes pod with a privileged container. This may indicate an adversary attempting to access that host's filesystem or gain root access to the host. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
Analytics BIOC Privileged role used by Azure application An Azure application with high-level API permissions invoked a request to the Microsoft Graph API. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion