Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
8 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. | High | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Credential Access |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics | EC2 backdoor created with newly added external SSH or RDP access EC2 instance created with an administrator instance profile and a newly added external SSH or RDP access. | High | Cortex Cloud | AWS Audit Log | Persistence |
| Correlation Rule | Microsoft Defender for Endpoint - Malware Detected This alert will trigger when Malware is detected by Microsoft Defender for Endpoint. | High | Enterprise Runtime Security, Cortex Cloud | Microsoft Defender Advanced Threat Protection, microsoft_365_defender_raw | |
| Analytics | Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Command and Control |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics | Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. | High | Cortex Cloud | AWS Audit Log | Impact |