Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. tactic: TA0005 ✕ technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Defense Evasion |
| Analytics BIOC | A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |
| Analytics BIOC | Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Persistence |
| Analytics | Short-lived user account A user was created and deleted within a short period of time. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. | Medium | Identity Analytics | AzureAD | Initial Access, Defense Evasion |
| Analytics BIOC | VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Defense Evasion |