Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

7 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access, Persistence
Analytics BIOC Azure application consent An identity consented permissions to an application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access, Credential Access
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC Invalid SAML Detected A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Okta Credential Access
Analytics Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Credential Access
Analytics BIOC Owner added to Azure application An identity was added as an owner to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access
Analytics Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Credential Access, Execution