Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

22 detectors match the current filters. technique: T1562 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Suppression Rule was created An Azure Suppression Rule was created. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion, Execution
Analytics BIOC Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion