Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
56 detectors match the current filters. tactic: TA0005 ✕ technique: T1562 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity created or modified a security group A cloud identity created or modified a security group. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| Analytics BIOC | AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| Analytics BIOC | An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Impact |
| Analytics BIOC | An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Suppression Rule was created An Azure Suppression Rule was created. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An identity disabled bucket logging An identity disabled bucket logging. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS network ACL rule deletion An AWS network ACL rule was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Impact |
| Analytics BIOC | Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Execution |
| Analytics BIOC | Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. | Informational | Cortex Cloud | Azure Audit Log | Execution, Persistence, Defense Evasion |
| Analytics BIOC | Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Watch alarm deletion A Cloud Watch alarm was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | CloudTrail logging deletion CloudTrail logging trail deletion. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Data encryption was disabled A cloud identity has disabled data encryption. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | GCP data asset shared public The GCP data asset was publicly shared. | Low | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Kubernetes cluster events deletion Kubernetes cluster events deletion. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics BIOC | Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. | Medium | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Defense Evasion |
| Analytics BIOC | MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |