Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. tactic: TA0006 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access
Analytics BIOC ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. Low Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC MFA Disabled for Google Workspace An administrator has disabled Multi-Factor Authentication for Google Workspace users. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access
Analytics BIOC MFA was disabled for an Azure identity MFA was disabled for the user. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access, Defense Evasion, Persistence
Analytics BIOC Unusual Azure AD sync module load A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module. Low Identity Threat Detection (ITDR) XDR Agent Credential Access