Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. tactic: TA0004 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A GCP service account was delegated domain-wide authority in Google Workspace A Google Workspace admin has enabled domain-wide delegation to a GCP service account. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | A Google Workspace service was configured as unrestricted An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Initial Access, Privilege Escalation |
| Analytics BIOC | A user accessed Okta's admin application An attempt to access Okta's admin management application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence, Privilege Escalation |
| Analytics BIOC | Admin privileges were granted to a Google Workspace user Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Gmail delegation was turned on for the organization A Google Workspace admin turned on Gmail delegation for all the organization's users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Google Marketplace restrictions were modified An identity modified Google Marketplace Restrictions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Google Workspace third-party application's security settings were changed An identity changed Google Workspace third-party application's security settings. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Okta admin privilege assignment A user assigned admin privileges to a new user or group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation |
| Analytics BIOC | Okta API Token Created A user created a new API token in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation, Execution, Persistence |