Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
41 detectors match the current filters. tactic: TA0001 ✕ technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A disabled user attempted to authenticate via SSO A disabled user attempted to authenticate via SSO. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | A disabled user attempted to log in A disabled user attempted to log in. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A disabled user attempted to log in to a VPN A disabled user attempted to log in suspiciously to a VPN. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | A possible risky login to Azure A risky sign-in attempt was observed in Azure. | Informational | Identity Analytics | AzureAD | Initial Access, Resource Development |
| Analytics BIOC | A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | A Successful login from TOR A successful login from a TOR exit node. | High | Identity Analytics | XDR Agent | Initial Access, Command and Control |
| Analytics BIOC | A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. | High | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Command and Control |
| Analytics BIOC | A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. | High | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access, Command and Control |
| Analytics BIOC | A user account was modified to password never expires A user account was modified to password never expires. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | An inactive user attempted to authenticate A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. | Informational | Identity Analytics | Initial Access | |
| Analytics BIOC | Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First SSO access from ASN for user A user successfully authenticated via SSO with a new ASN. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First SSO access from ASN in organization An SSO authentication was made with a new ASN. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Discovery |
| Analytics BIOC | First VPN access from ASN for user A user logged in to a VPN with a new ASN. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | First VPN access from ASN in organization A VPN connection was attempted from a new ASN. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics | Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Initial Access |
| Analytics BIOC | Interactive login by a machine account A machine account performed an interactive or remote interactive login. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Interactive login by a service account A service account performed an interactive or remote interactive login. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics | New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics | Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Resource Development |
| Analytics BIOC | SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a machine account A machine account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a service account A service account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. | Informational | Identity Analytics | AzureAD, Okta, OneLogin | Initial Access |
| Analytics BIOC | SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. | Informational | Identity Analytics | Okta, AzureAD, Azure SignIn Log, Duo, PingOne | Initial Access |
| Analytics BIOC | SSO with new operating system A user successfully authenticated via SSO with a new operating system. | Informational | Identity Analytics | Okta, Azure SignIn Log, AzureAD, Duo | Initial Access |
| Analytics BIOC | Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. | Informational | Identity Analytics | Initial Access | |
| Analytics BIOC | Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. | Medium | Identity Analytics | AzureAD | Initial Access, Defense Evasion |
| Analytics BIOC | Suspicious Azure AD interactive sign-in using PowerShell A user interactively logged in to Azure AD via PowerShell. | Informational | Identity Analytics | AzureAD | Initial Access |
| Analytics BIOC | Suspicious SSO access from ASN A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Suspicious SSO authentication A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | Okta | Initial Access |
| Analytics BIOC | Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login attempt by a honey user A VPN login attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login by a service account A service account attempted to log in to a VPN service. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login with a machine account A machine account successfully logged in to a VPN service. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |