Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

19 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Object versioning was disabled Object versioning of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Impact
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact