Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Defense Evasion |
| Analytics BIOC | A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |
| Analytics BIOC | Azure device code authentication flow used An Azure AD login was performed with device code flow. | Informational | Identity Analytics | Azure Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Modification of the AD FS IdentityServer configuration file The AD FS service configuration file was modified. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Defense Evasion |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics BIOC | User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Defense Evasion |
| Analytics BIOC | VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |