Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

17 detectors match the current filters. technique: T1098 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Google Workspace user was added to a group A user added another user to a Google Workspace group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure application credentials added An identity added credentials to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure application URI modification An identity added or updated an Azure application's URI. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Privilege Escalation
Analytics Exchange mailbox delegation permissions added A user added delegation permissions to an Exchange mailbox. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC Identity assigned an Azure AD Administrator Role An identity was assigned an Azure AD Administrator role. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC New Teams application published to the organization catalog A new Teams application was published to the organization catalog. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Okta admin privilege assignment A user assigned admin privileges to a new user or group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics BIOC SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Unverified domain added to Azure AD A new unverified domain was added to Azure AD. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC User added a new device to Okta Verify instance The user has successfully registered a new device with the Okta Verify application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Persistence