Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
24 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Execution |
| Analytics | Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics | AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Allocation of multiple cloud compute resources An identity allocated multiple compute resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics | Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. | Low | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Exfiltration, Collection |
| Analytics | Deletion of multiple cloud resources An identity deleted multiple cloud resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics | Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics | ML artifacts destruction An identity deleted multiple ML artifacts. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact |
| Analytics | Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery, Defense Evasion |
| Analytics | Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration |
| Analytics | Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics | New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics | Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics | Suspicious cloud user data modification attempt followed by VM restart Suspicious user data modification followed by VM restart, possibly an attempt to run altered startup scripts at boot. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics | Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |