Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
328 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | Suspicious AWS SSM parameters retrieval activity An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Collection |
| Analytics BIOC | Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Lateral Movement |
| Analytics BIOC | Suspicious ML Model Download A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. | Informational | Cortex Cloud | XDR Agent | Execution |
| Analytics | Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Exfiltration |
| Analytics BIOC | Unusual access to Microsoft 365 storage services Unusual access was detected to a Microsoft 365 storage service. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual AI model invocation A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | Unusual AWS Bedrock model access request A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | Unusual AWS CLI/SDK activity A cloud identity invoked an API using AWS CLI/SDK for the first time. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics | Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Unusual AWS SageMaker notebook access A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Lateral Movement |
| Analytics BIOC | Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |
| Analytics BIOC | Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | Unusual IAM enumeration activity by a non-user Identity An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity. | Informational | Cortex Cloud | Gcp Audit Log | Discovery |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual key management activity A cloud identity performed a key management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual Kubernetes secret access Suspicious Kubernetes secret access. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics | Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | Unusual resource access by Azure application An Azure application had interacted with an unusual resource using the Microsoft Graph API. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Privilege Escalation, Impact |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |