Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
23 detectors match the current filters. tactic: TA0005 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. | Informational | Identity Threat Detection (ITDR) | XDR Agent | Defense Evasion |
| Analytics BIOC | A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | A user modified an Okta network zone An Okta network zone was modified by a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion |
| Analytics BIOC | A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | BitLocker key retrieval An identity retrieved a BitLocker Key. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Lateral Movement |
| Analytics BIOC | Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Impact |
| Analytics BIOC | Device Registration Policy modification An identity changed the Device Registration policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Persistence |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics BIOC | Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics | Short-lived Azure AD user account An Azure AD user was created and deleted within a short period of time. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Unusual Conditional Access operation for an identity An identity attempted to add or update an Azure AD Conditional Access policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics | User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |