Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

35 detectors match the current filters. tactic: TA0005 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. Informational Identity Threat Detection (ITDR) XDR Agent Defense Evasion
Analytics BIOC A domain was added to the trusted domains list A domain was added to the Google Workspace trusted domains list. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A user modified an Okta network zone An Okta network zone was modified by a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. Medium Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Azure AD PIM role settings change An identity changed the PIM role settings. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure application credentials added An identity added credentials to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure application URI modification An identity added or updated an Azure application's URI. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC BitLocker key retrieval An identity retrieved a BitLocker Key. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
Analytics BIOC Conditional Access policy removed An identity removed a Conditional Access policy. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Impact
Analytics BIOC Device Registration Policy modification An identity changed the Device Registration policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC MFA was disabled for an Azure identity MFA was disabled for the user. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access, Defense Evasion, Persistence
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Persistence
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics Short-lived Azure AD user account An Azure AD user was created and deleted within a short period of time. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Unusual Conditional Access operation for an identity An identity attempted to add or update an Azure AD Conditional Access policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion