Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

64 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud instance was stopped A cloud compute instance was stopped. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC A container registry was created or deleted A container registry was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes Pod was deleted A Kubernetes Pod was deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes service was created or deleted A Kubernetes service was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An AWS SES identity was deleted An AWS SES identity has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure virtual network Device was modified An Azure virtual network Device was modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure virtual network was modified An Azure virtual network has been modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics BIOC Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC GCP IAM deny policy creation An identity created a GCP IAM deny policy. Low Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. Medium Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Defense Evasion
Analytics ML artifacts destruction An identity deleted multiple ML artifacts. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Object versioning was disabled Object versioning of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Impact
Analytics BIOC PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. Informational Cortex Cloud Azure Audit Log Impact
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC Suspicious AI Dataset Download A model dataset was accessed by an identity that typically doesn't interact with dataset files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Suspicious AI Dataset Label Modification AI Dataset labels were modified by an identity that typically doesn't interact with labels. MITRE ATLAS Technique: AML.T0020 - Poison Training Data. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Suspicious EBS snapshots deletion An identity deleted multiple EBS snapshots from the project, considerably more than usual. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. High Cortex Cloud AWS Audit Log Impact
Analytics BIOC Unusual AI dataset modification A cloud identity modified an AI dataset. MITRE ATLAS Techniques: AML.T0059 - Erode Dataset Integrity, AML.T0018.000 - Backdoor ML Model: Poison ML Model. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI Knowledge Base Modification An AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics BIOC Unusual AI RAG Knowledge Base Modification AI knowledge base was modified by an identity that typically doesn't interact with knowledge bases. MITRE ATLAS Technique: AML.T0070 - RAG Poisoning. OWASP Top 10 LLM Technique: LLM04 - Data and Model Poisoning. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact