Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
31 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | An Azure Key Vault key was modified An Azure Key Vault key was modified. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An Azure Key Vault was modified Azure Key Vault has been modified or deleted by an Identity. This could be an indication of unauthorized access or malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An identity accessed Azure Kubernetes Secrets An identity has accessed or attempted to access Azure Kubernetes secrets or Config Objects. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics BIOC | Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Granting Access to an Account Azure access has been granted to an account. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Credential Access |
| Analytics BIOC | Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Discovery |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Remote usage of an Azure Service Principal token An Azure Service Principal token was used externally of the cloud environment. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics | Suspicious access to cloud credential files A process accessed multiple cloud credential files, which may indicate a credential theft activity. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Suspicious AWS SSM parameters retrieval activity An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Collection |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Unusual access to the AD Sync credential files The AD Sync credential files were accessed in an unusual way. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. | Informational | Cortex Cloud | XDR Agent | Credential Access |
| Analytics BIOC | Unusual key management activity A cloud identity performed a key management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |
| Analytics BIOC | Unusual Kubernetes secret access Suspicious Kubernetes secret access. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | Unusual secret management activity A cloud Identity performed a secret management operation for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access |