Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
33 detectors match the current filters. tactic: TA0003 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Google Workspace identity created, assigned or modified a role A Google Workspace identity created, assigned or modified a delegated admin role. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | A Google Workspace identity performed an unusual admin console activity A Google Workspace identity performed an admin console activity for the first time. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | A Google Workspace user was added to a group A user added another user to a Google Workspace group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | A Microsoft Teams application was installed A Microsoft Teams application was installed. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | A Microsoft Teams bot was added to a team A user added a bot to a team in Microsoft Teams. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | A user accessed Okta's admin application An attempt to access Okta's admin management application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence, Privilege Escalation |
| Analytics BIOC | A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Credential Access, Persistence |
| Analytics BIOC | A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Authentication method added to an Azure account An identity attempted to add an Azure authentication method. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Initial Access, Persistence |
| Analytics | Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Persistence |
| Analytics BIOC | Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Persistence |
| Analytics BIOC | First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Google Workspace automation was created Google Workspace automation was created. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Execution, Persistence, Exfiltration |
| Analytics BIOC | Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access, Persistence |
| Analytics BIOC | Identity assigned an Azure AD Administrator Role An identity was assigned an Azure AD Administrator role. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | MFA was disabled for an Azure identity MFA was disabled for the user. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access, Defense Evasion, Persistence |
| Analytics BIOC | Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Persistence |
| Analytics BIOC | New Teams application published to the organization catalog A new Teams application was published to the organization catalog. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | Okta API Token Created A user created a new API token in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation, Execution, Persistence |
| Analytics | Okta device assignment A device was assigned as an Okta MFA device to a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence |
| Analytics BIOC | SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Suspicious MFA request reported by user in Entra ID A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Initial Access |
| Analytics BIOC | Unverified domain added to Azure AD A new unverified domain was added to Azure AD. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | User added a new device to Okta Verify instance The user has successfully registered a new device with the Okta Verify application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Persistence |
| Analytics BIOC | User installed an application in Microsoft Teams via Graph API A user who rarely uses the Graph API to install Microsoft Teams applications has installed one using it. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Microsoft Graph Logs | Persistence |