Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

4 detectors match the current filters. technique: T1530 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Credential Access
Analytics Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Collection
Analytics BIOC User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Collection