Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
4 detectors match the current filters. tactic: TA0009 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A user connected a new USB storage device to multiple hosts A user connected a new USB storage device to multiple endpoints. | Low | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics | User collected remote shared files in an archive Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration. | Low | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |