Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

15 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics Mailbox enumeration activity by Azure application Microsoft Graph API was used to enumerate mailboxes in Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft 365 storage services exfiltration activity The Microsoft Graph API was used to download Microsoft OneDrive and SharePoint files. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics Microsoft OneDrive enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneDrive items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneNote enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneNote items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft SharePoint enumeration activity The Microsoft Graph API was used to enumerate Microsoft SharePoint sites in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft Teams enumeration activity The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics Suspicious Azure enumeration activity An Azure identity performed resource enumeration across multiple services using Microsoft Graph. Medium Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Exfiltration
Analytics User sent messages in Microsoft Teams to multiple conversations via Graph API A user who rarely uses the Graph API for Microsoft Teams messaging sent multiple messages using it. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Microsoft Graph Logs Lateral Movement