Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

22 detectors match the current filters. tactic: TA0002 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Execution
Analytics BIOC A Kubernetes DaemonSet was created A Kubernetes DaemonSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes deployment was created A Kubernetes deployment was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes ephemeral container was created A Kubernetes ephemeral container was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes Pod was created with a sidecar container A Kubernetes Pod was created with a sidecar container. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes ReplicaSet was created A Kubernetes ReplicaSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes service account executed an unusual API call A Kubernetes service account executed an unusual API call. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC A Kubernetes StatefulSet was created A Kubernetes StatefulSet was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Cloud compute instance user data script modification The user data of a cloud compute instance was modified. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs Execution
Analytics BIOC Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod Created With Sensitive Volume An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Kubernetes pod creation with host network An identity created a Kubernetes pod attached to the host network. This may indicate an adversary attempting to access services bound to localhost, sniff traffic on any interface on the host, and potentially bypass the network policy. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Privileged Pod Creation An identity created a Kubernetes pod with a privileged container. This may indicate an adversary attempting to access that host's filesystem or gain root access to the host. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution, Discovery
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Unusual AI model invocation A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution