Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

12 detectors match the current filters. tactic: TA0001 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A disabled user attempted to log in A disabled user attempted to log in. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics BIOC Interactive login by a machine account A machine account performed an interactive or remote interactive login. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. Low Identity Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs Initial Access
Analytics BIOC Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. Informational Identity Analytics XDR Agent Initial Access