Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
12 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A disabled user attempted to authenticate via SSO A disabled user attempted to authenticate via SSO. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics | A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Discovery, Initial Access |
| Analytics BIOC | First SSO access from ASN for user A user successfully authenticated via SSO with a new ASN. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First SSO access from ASN in organization An SSO authentication was made with a new ASN. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Discovery |
| Analytics | Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Initial Access |
| Analytics | Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Resource Development |
| Analytics BIOC | SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. | Informational | Identity Analytics | AzureAD, Okta, OneLogin | Initial Access |
| Analytics BIOC | SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. | Informational | Identity Analytics | Okta, AzureAD, Azure SignIn Log, Duo, PingOne | Initial Access |
| Analytics BIOC | SSO with new operating system A user successfully authenticated via SSO with a new operating system. | Informational | Identity Analytics | Okta, Azure SignIn Log, AzureAD, Duo | Initial Access |
| Analytics BIOC | Suspicious SSO access from ASN A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Suspicious SSO authentication A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | Okta | Initial Access |