Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. tactic: TA0009 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics | External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics BIOC | Gmail routing settings changed Gmail routing settings were modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics | Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection, Credential Access |
| Analytics | Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Exfiltration, Collection |
| Analytics BIOC | User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Collection |