Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

397 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud compute instance user data script modification The user data of a cloud compute instance was modified. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics BIOC Cloud compute volume creation attempt An attempt was made to create an EBS volume. Informational Cortex Cloud AWS Audit Log Defense Evasion, Collection
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics BIOC Cloud email sending was enabled Cloud email sending was enabled for the cloud account. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Cloud email service activity A cloud Identity performed an email service operation. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Lateral Movement
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs Execution
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. Medium Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. Medium Cortex Cloud AWS Audit Log Execution, Lateral Movement
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. Informational Cortex Cloud AWS Audit Log Collection
Analytics BIOC EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. High Cortex Cloud AWS Audit Log Persistence
Analytics BIOC EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC External user invitation to Azure tenant An external user was invited to Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP data asset shared public The GCP data asset was publicly shared. Low Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP IAM deny policy creation An identity created a GCP IAM deny policy. Low Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. Low Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics BIOC GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP set IAM policy activity A cloud identity had modified a resource policy bindings. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM instance profile associations were described AWS IAM instance profile associations were described. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was created An AWS IAM instance profile was created. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy version was created A cloud identity created an AWS-managed IAM policy version. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to role An AWS IAM policy was attached to this role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role was created An IAM role was created. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
Analytics Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics BIOC Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution
Analytics BIOC Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation, Execution