Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. technique: T1562 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. | Informational | Identity Threat Detection (ITDR) | XDR Agent | Defense Evasion |
| Analytics BIOC | A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | A user modified an Okta network zone An Okta network zone was modified by a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion |
| Analytics BIOC | A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Lateral Movement |
| Analytics BIOC | Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Impact |
| Analytics BIOC | Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Persistence |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics BIOC | Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |