Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
45 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Microsoft Teams application was installed A Microsoft Teams application was installed. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | A Microsoft Teams bot was added to a team A user added a bot to a team in Microsoft Teams. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics | A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Lateral Movement, Execution |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics | Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Persistence |
| Analytics BIOC | Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Persistence |
| Analytics BIOC | Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics | External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics BIOC | External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Initial Access |
| Analytics | Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | Office 365 Audit | Impact |
| Analytics | Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Exfiltration, Collection |
| Analytics BIOC | Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Persistence |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics BIOC | Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | New Teams application published to the organization catalog A new Teams application was published to the organization catalog. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics | Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Impact |
| Analytics | Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. | Low | Identity Threat Detection (ITDR) | Office 365 Audit | Initial Access |
| Analytics | Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Initial Access |
| Analytics | Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. | High | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Command and Control |
| Analytics | User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics | User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |