Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
21 detectors match the current filters. tactic: TA0040 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud instance was stopped A cloud compute instance was stopped. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | A container registry was created or deleted A container registry was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes Pod was deleted A Kubernetes Pod was deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes service was created or deleted A Kubernetes service was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure virtual network Device was modified An Azure virtual network Device was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure virtual network was modified An Azure virtual network has been modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Impact |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Deletion of multiple cloud resources An identity deleted multiple cloud resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | Object versioning was disabled Object versioning of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Impact |
| Analytics BIOC | PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Privilege Escalation, Impact |