Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

328 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics Suspicious AWS SSM parameters retrieval activity An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. Informational Cortex Cloud AWS Audit Log Credential Access, Collection
Analytics BIOC Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Lateral Movement
Analytics BIOC Suspicious ML Model Download A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection
Analytics Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access, Collection
Analytics BIOC Uncommon cloud CLI tool usage An uncommon execution of a cloud CLI tool. Informational Cortex Cloud XDR Agent Execution
Analytics Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Exfiltration
Analytics BIOC Unusual access to Microsoft 365 storage services Unusual access was detected to a Microsoft 365 storage service. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. Informational Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual AI model invocation A cloud identity invoked an AI model for the first time. MITRE ATLAS Technique: AML.T0050 - Command and Scripting Interpreter. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Unusual AWS Bedrock model access request A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC Unusual AWS CLI/SDK activity A cloud identity invoked an API using AWS CLI/SDK for the first time. Informational Cortex Cloud AWS Audit Log Execution
Analytics Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Unusual AWS SageMaker notebook access A cloud identity accessed an AWS SageMaker notebook for the first time. MITRE ATLAS Technique: AML.T0008 - Acquire Infrastructure: AI Development Workspaces. Informational Cortex Cloud AWS Audit Log Execution
Analytics BIOC Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. Informational Cortex Cloud AWS Audit Log Discovery, Lateral Movement
Analytics BIOC Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. Informational Cortex Cloud XDR Agent Credential Access
Analytics BIOC Unusual exec into a Kubernetes Pod An identity initiated a shell session within a Kubernetes pod using the exec command. The command allows an identity to establish a temporary shell session and execute commands in the pod. This may indicate an attacker attempting to gain an interactive shell, which will allow access to the pod's data. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Unusual IAM enumeration activity by a non-user Identity An unusual command which may be related to an IAM recon enumeration was executed by a non-user identity. Informational Cortex Cloud Gcp Audit Log Discovery
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual key management activity A cloud identity performed a key management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual Kubernetes secret access Suspicious Kubernetes secret access. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC Unusual resource access by Azure application An Azure application had interacted with an unusual resource using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual secret management activity A cloud Identity performed a secret management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion