Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1677 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A TCP stream was created directly in a shell Attackers may create a TCP stream using the shell command line to generate a reverse shell, enabling remote access to the endpoint. Medium Platform Analytics XDR Agent Execution
Analytics BIOC A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Privilege Escalation
Analytics BIOC A third-party application's access to the Google Workspace domain's resources was revoked An identity removed a third-party application's access to Google Workspace domain's resources. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A third-party utility was copied to a different location To evade detection, attackers may copy a third-party utility executable to a different location. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics A user accessed an abnormal number of remote shared folders A user accessed an abnormal number of remote shared folders. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. Informational Identity Threat Detection (ITDR) Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics A user accessed multiple time-consuming websites A user was observed visiting multiple domains for personal reasons. Time theft happens when an employee is paid to work but did not actually work during that time. It might affect your business as it reduces the employee's efficiency. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall EAL Logs, XDR Agent Reconnaissance
Analytics A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Discovery, Initial Access
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user account was modified to password never expires A user account was modified to password never expires. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access
Analytics A user authenticated with weak NTLM to multiple hosts A user account authenticated to multiple hosts via NTLMv1 or LM authentication for the first time in the past 30 days. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user changed the Windows system time A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine. Informational Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics A user connected a new USB storage device to multiple hosts A user connected a new USB storage device to multiple endpoints. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user connected from a new country A user connected from an unusual country that the user has not connected from before. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC A user connected to a VPN from a new country A user connected to a VPN from an unusual country that the user has not connected from before. This may indicate the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC A user created a pfx file for the first time A user created a pfx file for the first time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC A user created an abnormal password-protected archive A user created an abnormal password-protected archive using an archive program. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics A user established an SMB connection to multiple hosts A user established an SMB connection to multiple hosts. This might indicate an enumeration attempt by a compromised account. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Defense Evasion
Analytics BIOC A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics BIOC A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. Informational Identity Analytics XDR Agent Credential Access, Resource Development
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access, Persistence
Analytics BIOC A user modified an Okta network zone An Okta network zone was modified by a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC A user modified the CA audit policy A user modified the CA audit policy. This may indicate that an attacker is attempting to cover their tracks before an AD CS attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics A user observed and reported unusual activity in Okta A user observed and reported unusual activity in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics A user performed suspiciously massive file activity A user generated massive file activity by size or distinct file count. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics A user printed an unusual number of files A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data. Informational Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Exfiltration
Analytics BIOC A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics A user received multiple weakly encrypted service tickets A user received multiple weakly encrypted service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user rejected an SSO request from an unusual country A user rejected an SSO authentication request from an abnormal country. Low Identity Analytics Okta, OneLogin Credential Access, Resource Development
Analytics A user requested multiple service tickets A user requested multiple service tickets. This is typically a sign of a Kerberoasting attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user sent multiple TGT requests to irregular service A user sent multiple TGT requests to services other than KRBTGT and KADMIN. This is typically a sign of a Kerberoasting attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics A user took numerous screenshots A user took numerous screenshots. A valuable organization's information may have been collected in this way. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. Low Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Lateral Movement, Execution
Analytics BIOC A user was added to a Windows security group A user was added to a Windows security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A WMI subscriber was created A WMI subscriber was created. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC Abnormal Communication to a Rare Domain An abnormal communication was seen from an internal entity to a rare domain. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Privilege Escalation
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
Analytics Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. Low Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics BIOC Abnormal network communication through TOR using an uncommon port Suspicious connection from a known TOR IP to an uncommon port. Low Platform Analytics XDR Agent Command and Control
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal process connection to default Meterpreter port This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. Informational Platform Analytics XDR Agent Command and Control
Analytics Abnormal RDP connections to multiple hosts The endpoint attempted to initiate rare RDP connections to multiple hosts. Informational Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal RDP connections to multiple hosts from a rarely seen host The endpoint attempted to initiate rare RDP connections to multiple hosts. Low Platform Analytics XDR Agent Lateral Movement
Analytics BIOC Abnormal RDP session to a remote host from a rarely seen host The endpoint performed a rare RDP session to a remote host. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Lateral Movement
Analytics BIOC Abnormal Recurring Communications to a Rare Domain Abnormal communications were seen from an internal entity to a rare external domain. This could be a case of beaconing to a C2 Server. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Command and Control
Analytics Abnormal RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Reconnaissance
Analytics Abnormal sensitive RPC traffic to multiple hosts The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host The endpoint performed unfamiliar RPC activity to multiple hosts using a known sensitive interface. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement
Analytics Abnormal SMB activity to multiple hosts An endpoint performed a new, unfamiliar SMB activity to multiple hosts on the network. Low Platform Analytics XDR Agent Lateral Movement
Analytics Abnormal SMB scanning activity to multiple hosts An endpoint performed a new, unfamiliar SMB scanning activity to multiple hosts on the network. Informational Platform Analytics XDR Agent Reconnaissance
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics BIOC Access to kubelet credentials file A process accessed a kubelet credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
BIOC Accessing bash history file Clearing bash history file is a known procedure of attackers to delete traces. Low Platform Analytics Process execution Defense Evasion
BIOC Accessing bash history file using bash commands Clearing bash history files is a known attacker procedure for covering their tracks. Low Platform Analytics Process execution Defense Evasion
BIOC Account creation via command-line tool The useradd/adduser command could be used to create user accounts or to add users to existing groups. Informational Platform Analytics Process execution Persistence
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
BIOC Active Setup Registry Autostart Suspicious modification of the active setup registry for persistence and privilege escalation. Low Platform Analytics Registry Persistence
Analytics BIOC Adding execution privileges A script was granted execution privileges using chmod before being run. Informational Platform Analytics XDR Agent Execution
BIOC ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). Informational Platform Analytics Process execution Discovery
Analytics BIOC ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. Low Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Admin privileges were granted to a Google Workspace user Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
BIOC Administrator obtains access rights to a file using icacls.exe Grant an administrator file access privileges. Informational Platform Analytics Process execution Defense Evasion
BIOC Adobe Acrobat Reader drops an executable file to disk The Acrobat Reader process dropped a new executable file to the disk. Unusual activity, possibly indicative of exploitation or social engineering attempt. Informational Platform Analytics File Initial Access
BIOC Adobe reader spawns a browser If a user clicks a URL link contained in a PDF document, it will cause the Adobe Reader process to spawn a browser process. It has legitimate uses, but check for possible phishing attempts. Informational Platform Analytics Process execution Initial Access
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Analytics AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. Informational Platform Analytics Palo Alto Networks Platform Alerts, Third-Party Alerts Execution
Correlation Rule Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account Medium Platform Analytics alibaba_action_trail_raw
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
BIOC AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. Medium Platform Analytics Process execution Defense Evasion
Analytics BIOC An app was added to Google Marketplace An app was added to the Google Workspace Marketplace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Command and Control
Analytics BIOC An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration