Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. Informational Identity Threat Detection (ITDR) Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics A user accessed multiple time-consuming websites A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics BIOC Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. Informational Platform Analytics Palo Alto Networks Firewall threat Logs, XDR Agent Reconnaissance
Analytics Increase in Job-Related Site Visits A user has visited multiple job-related sites in the past day. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics Massive upload to a rare storage or mail domain A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent Exfiltration
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics BIOC Recurring access to rare domain The endpoint is periodically connecting to an external domain (categorized as malware) that it and its peers rarely use. Access to this domain has occurred repeatedly over multiple days. This connection pattern is consistent with malware connecting to its command and control server for updates and operating instructions. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent, Third-Party Firewalls Command and Control