Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

50 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Microsoft Teams application was installed A Microsoft Teams application was installed. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC A Microsoft Teams bot was added to a team A user added a bot to a team in Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. Low Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Lateral Movement, Execution
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics BIOC External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
Analytics Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Exfiltration, Collection
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Persistence
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics BIOC New Teams application published to the organization catalog A new Teams application was published to the organization catalog. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Penetration testing tool activity attempt A SaaS API was invoked by a penetration testing tool. Informational Identity Analytics Office 365 Audit Execution
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. Low Identity Threat Detection (ITDR) Office 365 Audit Initial Access
Analytics Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. Medium Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Initial Access
Analytics BIOC Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. Informational Email Security Office 365 Audit Collection
Analytics BIOC SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Initial Access
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. High Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Command and Control
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact
Analytics User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics BIOC User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Collection
Analytics User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion