Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
14 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log | Exfiltration |
| Analytics BIOC | A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics BIOC | A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Initial Access |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. | Medium | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics | Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. | Medium | Cortex Cloud | AWS Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution, Discovery |
| Analytics BIOC | Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. | Medium | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Defense Evasion |
| Analytics | Suspicious Azure enumeration activity An Azure identity performed resource enumeration across multiple services using Microsoft Graph. | Medium | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. | Medium | Cortex Cloud | XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | Unusual process executed by AWS Systems Manager An unusual process was executed by the AWS Systems Manager agent. Adversaries may use the Systems Manager agent to execute malicious commands on an endpoint. | Medium | Cortex Cloud | XDR Agent | Execution |