Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
21 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud storage configuration was modified A cloud storage configuration was modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure SQL database was exported from a production subscription An Azure SQL database export was initiated. The database was exported from a production subscription. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated for export from a production subscription A SAS URL for an Azure VM snapshot was generated. The operation was performed within a production subscription. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. | Low | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Exfiltration, Collection |
| Analytics | Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration |
| Analytics BIOC | Object versioning was disabled Object versioning of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Impact |
| Analytics BIOC | Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics | Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |