Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. | Medium | Cortex Cloud | XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. | Informational | Cortex Cloud | XDR Agent | Execution |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |
| Analytics BIOC | Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. | Medium | Cortex Cloud | XDR Agent | Execution |