Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. technique: T1021 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Lateral Movement |
| Analytics BIOC | An identity started an AWS SSM session An identity started an AWS SSM interactive session. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics BIOC | AWS SSM send command attempt An identity executed an AWS SSM Document. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement, Execution |
| Analytics BIOC | Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Lateral Movement |
| Analytics BIOC | Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. | Informational | Cortex Cloud | Azure Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Lateral Movement |
| Analytics | Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. | Medium | Cortex Cloud | AWS Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Serial console access was enabled in AWS account Serial console access to EC2 instances was enabled in an AWS account. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics BIOC | Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Lateral Movement |
| Analytics BIOC | Unusual AWS systems manager activity A cloud identity performed an SSM operation for the first time. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Lateral Movement |