Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

20 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. Low Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Lateral Movement, Execution
Analytics Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. Medium Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
Analytics Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Exfiltration, Collection
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. Low Identity Threat Detection (ITDR) Office 365 Audit Initial Access
Analytics Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics Potential extraction of NAA Account Credentials in Microsoft Configuration Manager Possible user attempt to deobfuscate Network Access Account (NAA) credentials in Microsoft Configuration Manager. This may indicate a compromised account. Low Identity Analytics AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Defense Evasion
Analytics Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. Medium Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Initial Access
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact
Analytics User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion