Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
31 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Authentication method added to an Azure account An identity attempted to add an Azure authentication method. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure account deletion by a non-standard account An Azure AD account deletion was performed by a user that doesn't typically delete users. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Impact |
| Analytics BIOC | Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. | Medium | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | BitLocker key retrieval An identity retrieved a BitLocker Key. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Conditional Access policy removed An identity removed a Conditional Access policy. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Device Registration Policy modification An identity changed the Device Registration policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access |
| Analytics BIOC | First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Identity assigned an Azure AD Administrator Role An identity was assigned an Azure AD Administrator role. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | MFA was disabled for an Azure identity MFA was disabled for the user. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access, Defense Evasion, Persistence |
| Analytics | Multiple Azure AD admin role removals An Azure AD identity removed multiple administrators from their roles. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Impact |
| Analytics BIOC | Owner added to Azure application An identity was added as an owner to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access |
| Analytics | Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics | Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics | Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. | Low | Identity Analytics | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics | Short-lived Azure AD user account An Azure AD user was created and deleted within a short period of time. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Suspicious MFA request reported by user in Entra ID A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Initial Access |
| Analytics BIOC | Unusual Conditional Access operation for an identity An identity attempted to add or update an Azure AD Conditional Access policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Unverified domain added to Azure AD A new unverified domain was added to Azure AD. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |