Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Credential Access |
| Analytics BIOC | Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Discovery |
| Analytics BIOC | Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual key management activity A cloud identity performed a key management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual Kubernetes secret access Suspicious Kubernetes secret access. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |