Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection, Credential Access |
| Analytics | Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | Google Workspace Audit Logs | Impact |
| Analytics | Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Exfiltration, Collection |
| Analytics | Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. | Medium | Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log | Initial Access |
| Analytics | Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. | Informational | Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log | Impact |