Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

38 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A cloud storage configuration was modified A cloud storage configuration was modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics BIOC A Service Principal was removed from Azure A service principal was removed from Azure. This indicates a change in access permissions and may indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Suppression Rule was created An Azure Suppression Rule was created. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure application removed An Azure application has been deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure conditional access policy creation or modification An Azure conditional access policy was created or modified. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Defense Evasion
Analytics BIOC Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure mailbox rule creation A Mailbox rule in Azure was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection, Defense Evasion
Analytics BIOC Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion, Execution
Analytics BIOC Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. Informational Cortex Cloud Azure Audit Log Defense Evasion, Lateral Movement
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Analytics BIOC Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics BIOC Removal of an Azure Owner from an Application or Service Principal An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion