Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

119 detectors match the current filters. technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. Informational Identity Analytics Initial Access
Analytics BIOC Successful unusual guest user invitation An identity successfully invited a guest user to the tenant with unusual characteristics. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Suspicious Azure AD interactive sign-in using PowerShell A user interactively logged in to Azure AD via PowerShell. Informational Identity Analytics AzureAD Initial Access
Analytics BIOC Suspicious MFA request reported by user in Entra ID A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Initial Access
Analytics BIOC Suspicious SSO access from ASN A suspicious SSO authentication was made by a user. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC Suspicious SSO authentication A suspicious SSO authentication was made by a user. Informational Identity Analytics Okta Initial Access
Analytics BIOC Unusual AWS Bedrock model access request A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Privilege Escalation, Defense Evasion, Initial Access
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
Analytics BIOC Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Persistence, Privilege Escalation, Defense Evasion
BIOC User account flagged as hidden Look for unsigned processes that add an entry to the hidden users Registry key. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC User added a new device to Okta Verify instance The user has successfully registered a new device with the Okta Verify application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Persistence
Analytics User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC User signed in to an application via Power Automate for the first time A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Exfiltration
Analytics BIOC VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics BIOC VPN login with a machine account A machine account successfully logged in to a VPN service. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access