Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

20 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud function was created with an unusual runtime A cloud function was created with an unusual runtime. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. Low Cortex Cloud Gcp Audit Log Initial Access, Credential Access
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics BIOC GCP data asset shared public The GCP data asset was publicly shared. Low Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP IAM deny policy creation An identity created a GCP IAM deny policy. Low Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. Low Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Kubernetes pod creation from unknown container image registry A Kubernetes pod was created with a container image from an unknown registry. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics ML artifacts destruction An identity deleted multiple ML artifacts. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC Unusual AI dataset modification A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI Knowledge Base Modification An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI RAG Knowledge Base Modification AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual cross projects activity A suspicious activity between different cloud projects. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access