Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics A user accessed an abnormal number of remote shared folders A user accessed an abnormal number of remote shared folders. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics A user performed suspiciously massive file activity A user generated massive file activity by size or distinct file count. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Massive file activity abnormal to process A user generated massive file activity by size or distinct file count. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Suspicious access to Kubernetes API with kubelet credentials A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster. Low Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Exfiltration, Collection