Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

328 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Authentication method was added to Azure account A new authentication method was added to an Azure AD user. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. Informational Cortex Cloud AWS Audit Log Impact
Analytics AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. Informational Cortex Cloud AWS Audit Log Impact
Analytics AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS root account activity The AWS root account has successfully performed an operation in the project. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS SecurityHub findings were modified AWS SecurityHub findings were modified. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC AWS SSM send command attempt An identity executed an AWS SSM Document. Informational Cortex Cloud AWS Audit Log Lateral Movement, Execution
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS user creation A new AWS user was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Azure application removed An Azure application has been deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure conditional access policy creation or modification An Azure conditional access policy was created or modified. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Defense Evasion
Analytics BIOC Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Azure Event Hub Authorization rule creation/modification An authorization rule is bound with specific rights, once created within a namespace, which has management permissions. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure group creation/deletion A group in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure mailbox rule creation A Mailbox rule in Azure was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection, Defense Evasion
Analytics BIOC Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion, Execution
Analytics BIOC Azure permission delegation granted An identity delegated permissions to access a certain resource or application. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. Informational Cortex Cloud Azure Audit Log Defense Evasion, Lateral Movement
Analytics BIOC Azure Service principal/Application creation An Azure Service principal/Application was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Analytics BIOC Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure user creation/deletion A user in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure user password reset The password of an Azure AD user was reset. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. Informational Cortex Cloud Azure Audit Log Execution, Lateral Movement
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
Analytics BIOC BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC Bucket's block public access setting turned off S3 bucket block public access setting turned off. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud compute instance user data script modification The user data of a cloud compute instance was modified. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics BIOC Cloud compute volume creation attempt An attempt was made to create an EBS volume. Informational Cortex Cloud AWS Audit Log Defense Evasion, Collection
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics BIOC Cloud email sending was enabled Cloud email sending was enabled for the cloud account. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Cloud email service activity A cloud Identity performed an email service operation. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Lateral Movement
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion