Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. tactic: TA0005 ✕ technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Defense Evasion
Analytics BIOC A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics BIOC Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics XDR Agent Defense Evasion
Analytics BIOC Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics Short-lived user account A user was created and deleted within a short period of time. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. Medium Identity Analytics AzureAD Initial Access, Defense Evasion
Analytics BIOC VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion