Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
20 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. | Low | Cortex Cloud | Gcp Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics | Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Command and Control |
| Analytics BIOC | Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. | Informational | Cortex Cloud | Gcp Audit Log | Privilege Escalation, Initial Access |
| Analytics | Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics | Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics BIOC | Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual cross projects activity A suspicious activity between different cloud projects. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |