Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
12 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A disabled user attempted to log in A disabled user attempted to log in. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A Successful login from TOR A successful login from a TOR exit node. | High | Identity Analytics | XDR Agent | Initial Access, Command and Control |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Interactive login by a machine account A machine account performed an interactive or remote interactive login. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Interactive login by a service account A service account performed an interactive or remote interactive login. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics | New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. | Low | Identity Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs | Initial Access |
| Analytics BIOC | Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. | Informational | Identity Analytics | XDR Agent | Initial Access |