Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

19 detectors match the current filters. technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion