Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. technique: T1531 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. | Informational | Cortex Cloud | Azure Audit Log | Impact |