Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

108 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. Informational Identity Threat Detection (ITDR) XDR Agent Defense Evasion
Analytics BIOC A domain was added to the trusted domains list A domain was added to the Google Workspace trusted domains list. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC A GCP service account was delegated domain-wide authority in Google Workspace A Google Workspace admin has enabled domain-wide delegation to a GCP service account. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC A Google Workspace identity created, assigned or modified a role A Google Workspace identity created, assigned or modified a delegated admin role. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace identity performed an unusual admin console activity A Google Workspace identity performed an admin console activity for the first time. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC A Google Workspace Role privilege was deleted A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A Google Workspace service was configured as unrestricted An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC A Google Workspace user was added to a group A user added another user to a Google Workspace group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace user was removed from a group A user removed another user from a Google Workspace group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A mail forwarding rule was configured in Google Workspace A rule was set up to forward emails outside the Google Workspace domain. Medium Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Exfiltration
Analytics BIOC A Microsoft Teams application was installed A Microsoft Teams application was installed. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC A Microsoft Teams bot was added to a team A user added a bot to a team in Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Privilege Escalation
Analytics BIOC A third-party application's access to the Google Workspace domain's resources was revoked An identity removed a third-party application's access to Google Workspace domain's resources. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. Informational Identity Threat Detection (ITDR) Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access
Analytics BIOC A user changed the Windows system time A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine. Informational Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user created an abnormal password-protected archive A user created an abnormal password-protected archive using an archive program. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access, Persistence
Analytics BIOC A user modified an Okta network zone An Okta network zone was modified by a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. Low Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Admin privileges were granted to a Google Workspace user Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC An app was added to Google Marketplace An app was added to the Google Workspace Marketplace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Command and Control
Analytics BIOC An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Authentication method added to an Azure account An identity attempted to add an Azure authentication method. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure account deletion by a non-standard account An Azure AD account deletion was performed by a user that doesn't typically delete users. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Impact
Analytics BIOC Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. Medium Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure AD PIM role settings change An identity changed the PIM role settings. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure application consent An identity consented permissions to an application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access, Credential Access
Analytics BIOC Azure application credentials added An identity added credentials to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure application URI modification An identity added or updated an Azure application's URI. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Privilege Escalation
Analytics BIOC Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC BitLocker key retrieval An identity retrieved a BitLocker Key. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Persistence
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
Analytics BIOC Conditional Access policy removed An identity removed a Conditional Access policy. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Impact
Analytics BIOC Device Registration Policy modification An identity changed the Device Registration policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange email-hiding inbox rule A user configured an Exchange inbox rule that may be used to hide emails. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange email-hiding transport rule A user configured an Exchange transport rule that may be used to hide emails in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC External Sharing was turned on for Google Drive An identity has modified Google Drive sharing settings and allowed external sharing. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Exfiltration
Analytics BIOC External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics BIOC First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access
Analytics BIOC First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Gmail delegation was turned on for the organization A Google Workspace admin turned on Gmail delegation for all the organization's users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Gmail routing settings changed Gmail routing settings were modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC Google Marketplace restrictions were modified An identity modified Google Marketplace Restrictions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Google Workspace automation was created Google Workspace automation was created. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Execution, Persistence, Exfiltration
Analytics BIOC Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC Google Workspace third-party application's security settings were changed An identity changed Google Workspace third-party application's security settings. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC Identity assigned an Azure AD Administrator Role An identity was assigned an Azure AD Administrator role. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Invalid SAML Detected A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Okta Credential Access
Analytics BIOC MFA Disabled for Google Workspace An administrator has disabled Multi-Factor Authentication for Google Workspace users. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access
Analytics BIOC MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC MFA was disabled for an Azure identity MFA was disabled for the user. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access, Defense Evasion, Persistence
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Persistence
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics BIOC New Teams application published to the organization catalog A new Teams application was published to the organization catalog. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Okta account unlock by admin An administrative user unlocked an Okta account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta admin privilege assignment A user assigned admin privileges to a new user or group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics BIOC Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta User Session Impersonation A user has initiated a session impersonation in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Owner added to Azure application An identity was added as an owner to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access
Analytics BIOC Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Collection, Initial Access
Analytics BIOC Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs, Office 365 Audit Initial Access
Analytics BIOC Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Suspicious MFA request reported by user in Entra ID A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Initial Access