Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
153 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Cloud DB instance was exported to an unknown destination A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | A cloud identity created or modified a security group A cloud identity created or modified a security group. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence |
| Analytics | A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | A cloud instance was stopped A cloud compute instance was stopped. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | A cloud storage configuration was modified A cloud storage configuration was modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. | Low | Cortex Cloud | Gcp Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A container registry was created or deleted A container registry was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A GCP Cloud SQL DB instance was exported from a production account A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes Cronjob was created A Kubernetes CronJob was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes DaemonSet was created A Kubernetes DaemonSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes deployment was created A Kubernetes deployment was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes ephemeral container was created A Kubernetes ephemeral container was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes namespace was created or deleted A Kubernetes namespace was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics BIOC | A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes Pod was created with a sidecar container A Kubernetes Pod was created with a sidecar container. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes Pod was deleted A Kubernetes Pod was deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes ReplicaSet was created A Kubernetes ReplicaSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | A Kubernetes service account executed an unusual API call A Kubernetes service account executed an unusual API call. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics BIOC | A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes service was created or deleted A Kubernetes service was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes StatefulSet was created A Kubernetes StatefulSet was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics | Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics | AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration, Defense Evasion |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | Billing admin role was removed Sensitive Action - Billing admin role was removed. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud access key creation Cloud access key creation by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Command and Control |
| Analytics BIOC | Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud compute instance user data script modification The user data of a cloud compute instance was modified. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Lateral Movement |
| Analytics BIOC | Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | Cloud instance creation attempt An attempt was made to create a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics | Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. | Low | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Exfiltration, Collection |
| Analytics | Deletion of multiple cloud resources An identity deleted multiple cloud resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP data asset shared public The GCP data asset was publicly shared. | Low | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP IAM deny policy creation An identity created a GCP IAM deny policy. | Low | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. | Low | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics BIOC | GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. | Informational | Cortex Cloud | Gcp Audit Log | Privilege Escalation, Initial Access |
| Analytics BIOC | GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |