Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

19 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Cloud DB instance was exported to an unknown destination A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC A cloud storage configuration was modified A cloud storage configuration was modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A GCP Cloud SQL DB instance was exported from a production account A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. Informational Cortex Cloud Gcp Audit Log Exfiltration, Defense Evasion
Analytics BIOC BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics BIOC GCP data asset shared public The GCP data asset was publicly shared. Low Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration
Analytics Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration