Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. tactic: TA0011 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An Azure DNS Zone was modified An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration. Informational Cortex Cloud Azure Audit Log Command and Control
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. High Cortex Cloud AWS Audit Log, Gcp Audit Log Command and Control
Analytics BIOC Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Command and Control, Initial Access
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration