Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
12 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Credential Access |
| Analytics BIOC | A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Credential Access, Persistence |
| Analytics BIOC | ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. | Low | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access, Persistence |
| Analytics BIOC | Invalid SAML Detected A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD, Okta | Credential Access |
| Analytics | Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection, Credential Access |
| Analytics BIOC | MFA Disabled for Google Workspace An administrator has disabled Multi-Factor Authentication for Google Workspace users. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access |
| Analytics BIOC | MFA was disabled for an Azure identity MFA was disabled for the user. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access, Defense Evasion, Persistence |
| Analytics BIOC | Owner added to Azure application An identity was added as an owner to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| Analytics BIOC | Unusual Azure AD sync module load A process that does not usually load the Azure AD Sync mcrypt.dll loaded the module. | Low | Identity Threat Detection (ITDR) | XDR Agent | Credential Access |