Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. tactic: TA0004 ✕ technique: T1098 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. | Low | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |