Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

25 detectors match the current filters. tactic: TA0003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes Cronjob was created A Kubernetes CronJob was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. Low Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP set IAM policy activity A cloud identity had modified a resource policy bindings. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role was created An IAM role was created. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Lateral Movement
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion