Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

18 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics Microsoft 365 storage services exfiltration activity The Microsoft Graph API was used to download Microsoft OneDrive and SharePoint files. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Privileged role used by Azure application An Azure application with high-level API permissions invoked a request to the Microsoft Graph API. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation
Analytics BIOC Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. Low Cortex Cloud Azure Audit Log Credential Access
Analytics Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. Low Cortex Cloud AWS Audit Log, Azure Audit Log Execution
Analytics BIOC Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC Uncommon Azure Cosmos DB master key read by identity A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity. Low Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Unusual AI dataset modification A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual cross projects activity A suspicious activity between different cloud projects. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access