Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

16 detectors match the current filters. tactic: TA0004 ✕ technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. Informational Cortex Cloud Azure Audit Log Initial Access, Privilege Escalation
Analytics BIOC An Azure Kubernetes Role or Cluster-Role was modified An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted. This could indicate a security breach or malicious activity. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion