Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
397 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud access key creation Cloud access key creation by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Command and Control |
| Analytics BIOC | Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud compute instance user data script modification The user data of a cloud compute instance was modified. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Lateral Movement |
| Analytics BIOC | Cloud compute volume creation attempt An attempt was made to create an EBS volume. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Collection |
| Analytics | Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Discovery |
| Analytics BIOC | Cloud email sending was enabled Cloud email sending was enabled for the cloud account. | Informational | Cortex Cloud | AWS Audit Log | Resource Development |
| Analytics BIOC | Cloud email service activity A cloud Identity performed an email service operation. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Lateral Movement |
| Analytics BIOC | Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Initial Access |
| Analytics | Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | Cloud instance creation attempt An attempt was made to create a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. | Medium | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics | Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | Cloud Watch alarm deletion A Cloud Watch alarm was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | CloudTrail logging deletion CloudTrail logging trail deletion. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. | Medium | Cortex Cloud | AWS Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Credentials were added to Azure application Credentials were added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | Data encryption was disabled A cloud identity has disabled data encryption. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. | Low | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Exfiltration, Collection |
| Analytics | Deletion of multiple cloud resources An identity deleted multiple cloud resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. | Low | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| Analytics BIOC | EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. | High | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | External user invitation to Azure tenant An external user was invited to Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP data asset shared public The GCP data asset was publicly shared. | Low | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP IAM deny policy creation An identity created a GCP IAM deny policy. | Low | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. | Low | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics BIOC | GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. | Informational | Cortex Cloud | Gcp Audit Log | Privilege Escalation, Initial Access |
| Analytics BIOC | GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Granting Access to an Account Azure access has been granted to an account. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Credential Access |
| Analytics | IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM instance profile associations were described AWS IAM instance profile associations were described. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was created An AWS IAM instance profile was created. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy version was created A cloud identity created an AWS-managed IAM policy version. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to role An AWS IAM policy was attached to this role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | IAM User added to an IAM group An IAM user was added to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics | Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Credential Access |
| Analytics BIOC | Kubernetes cluster events deletion Kubernetes cluster events deletion. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics | Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics BIOC | Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| Analytics BIOC | Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |