Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

171 detectors match the current filters. tactic: TA0001 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. Low Cortex Cloud Gcp Audit Log Initial Access, Credential Access
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. Informational Cortex Cloud AWS Audit Log Initial Access, Credential Access
Analytics BIOC A disabled user attempted to authenticate via SSO A disabled user attempted to authenticate via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC A disabled user attempted to log in A disabled user attempted to log in. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A disabled user attempted to log in to a VPN A disabled user attempted to log in suspiciously to a VPN. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes dashboard service account was used outside the cluster A Kubernetes dashboard service account was successfully used externally of the Kubernetes environment, which may indicate that the dashboard is exposed to the internet and does not require authentication. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A possible risky login to Azure A risky sign-in attempt was observed in Azure. Informational Identity Analytics AzureAD Initial Access, Resource Development
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. Informational Cortex Cloud Azure Audit Log Initial Access, Privilege Escalation
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. High Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Command and Control
Analytics BIOC A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. High Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access, Command and Control
Analytics BIOC A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Privilege Escalation
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Discovery, Initial Access
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user account was modified to password never expires A user account was modified to password never expires. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics A user observed and reported unusual activity in Okta A user observed and reported unusual activity in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
BIOC Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. Informational Platform Analytics File Initial Access
BIOC Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. Informational Platform Analytics Process execution Initial Access
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An AWS SAML provider was modified An AWS SAML provider was modified. Informational Cortex Cloud AWS Audit Log Initial Access, Defense Evasion
Analytics BIOC An inactive user attempted to authenticate A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. Informational Identity Analytics Initial Access
Analytics BIOC An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. High Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Credential Access
Analytics BIOC Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Initial Access
Analytics BIOC Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS root account activity The AWS root account has successfully performed an operation in the project. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC Azure application consent An identity consented permissions to an application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access, Credential Access
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Correlation Rule Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. Medium Platform Analytics google_workspace_chrome_raw Initial Access
Analytics BIOC Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Persistence
Analytics BIOC ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Initial Access
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. Medium Cortex Cloud AWS Audit Log, XDR Agent Initial Access, Credential Access
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Display text URL differs from actual URL An email contains a hyperlink whose display text shows a URL different from the actual destination URL. Informational Email Security Microsoft 365 Emails Initial Access
Analytics Download pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Command and Control, Initial Access
Analytics BIOC Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email mimics replies or forwards without an actual ongoing conversation An email with a subject line or body that includes signs of a reply or forward without an actual ongoing conversation. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email sent using an automated system or script detected The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email was received from an unknown sender using a disposable domain The email was received from an unknown sender using a disposable email provider, first seen in the organization in the past month. Low Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. Low Email Security Microsoft 365 Emails Initial Access, Execution
BIOC Excel Web Query file created on disk Excel uses Excel Web Query (.iqy) files to download data from the internet. There are campaigns in which .iqy files download a PowerShell script, which is launched via Excel and kicks off a chain of malicious downloads. Informational Platform Analytics File Initial Access
Analytics BIOC Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
BIOC Exchange process writing aspx files An exchange process is writing to .aspx files. This may be an actor dropping web shells. High Platform Analytics File Initial Access, Command and Control
Analytics BIOC Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion, Initial Access
Analytics BIOC Executable or Script file written by a web server process An uncommon executable or script file was created, written, or renamed by a web server process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics BIOC External user added a link to a Microsoft Teams chat An external user added a link to a Microsoft Teams chat. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user call via Microsoft Teams An external user called a user in the organization via Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user created a Microsoft Teams conversation with suspicious operations An external user created a Microsoft Teams conversation with users in the organization with additional suspicious operations. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics External user started a Microsoft Teams conversation An external user started a Microsoft Teams conversation with users in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Initial Access
Analytics BIOC Failed Login For a Long Username With Special Characters A long username containing special characters failed to log in to the domain. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Initial Access
Analytics BIOC First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access
Analytics BIOC First SSO access from ASN for user A user successfully authenticated via SSO with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO access from ASN in organization An SSO authentication was made with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Discovery
Analytics BIOC First VPN access from ASN for user A user logged in to a VPN with a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC First VPN access from ASN in organization A VPN connection was attempted from a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics Impossible travel by a cloud identity Cloud identity activity detected from distant geographic regions within an short time window. This suggests unauthorized use of credentials, possibly indicating a compromised account. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Initial Access
Analytics BIOC Interactive login by a machine account A machine account performed an interactive or remote interactive login. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Microsoft Office injects code into a process An attacker may inject payloads into processes via Microsoft Office. While legitimate in certain cases, code injection can also be used in malicious ways. Low Platform Analytics XDR Agent Initial Access, Defense Evasion
Analytics BIOC Microsoft Office Process Spawning a Suspicious One-Liner A Microsoft Office process spawned a commonly abused process with a full command (not a script), this is a typically malicious behavior. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns a commonly abused process Microsoft Office process spawns a commonly abused process with an uncommon command. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics BIOC Microsoft Office process spawns conhost.exe This unusual parent-child relationship may indicate that a Microsoft Office application executed a console-based application. Low Platform Analytics XDR Agent Execution, Initial Access
Analytics Multiple failed logins from a single IP Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Multiple risk indicators for a cloud identity Multiple risk indicators detected for a cloud identity, combining unusual activity with activity from unusual geolocation or high-risk IP. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics Numerous emails sent by a single sender to multiple internal recipients Numerous emails were sent to multiple internal recipients. This may indicate spam or any other malicious attempt. Informational Email Security Microsoft 365 Emails Initial Access
BIOC Office document embeds a .LNK file An Office process spawned a process with an argument indicating that the document contains an embedded .LNK file. Informational Platform Analytics Process execution Initial Access
BIOC Office process spawns verclsid.exe A Microsoft Office process launching verclsid.exe may be a sign of phishing. Informational Platform Analytics Process execution Initial Access
Analytics Okta account reset password attempt A user used a weak factor to reset their Okta password. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics Okta account unlock Okta user account was unlocked. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta account unlock by admin An administrative user unlocked an Okta account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access