Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Credential Access
Analytics Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Google Workspace Audit Logs Impact
Analytics Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Exfiltration, Collection
Analytics Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. Medium Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Initial Access
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact