Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
171 detectors match the current filters. tactic: TA0001 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Okta device assignment A device was assigned as an Okta MFA device to a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence |
| Analytics BIOC | Okta FastPass reported phishing attack suspected Okta FastPass authentication reported a phishing attack suspected. | Low | Identity Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent, Palo Alto Networks Firewall threat Logs | Initial Access |
| Analytics BIOC | Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access |
| Analytics | Okta Reported Threat Detected Okta Threat Insight Reported Threat Detected. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access |
| Analytics BIOC | Okta User Session Impersonation A user has initiated a session impersonation in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access |
| BIOC | Out of band testing domain connection Connection from web service process to out-of-band-testing domain. | Low | Platform Analytics | Network | Initial Access |
| BIOC | Outlook creates an executable file on disk Common weaponized Office document behavior, as Outlook should not create binary files at all. | Informational | Platform Analytics | File | Initial Access |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| Analytics | Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Resource Development |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics | Possible multistage attack in Microsoft Teams Possible multistage attack in Microsoft Teams. | Low | Identity Threat Detection (ITDR) | Office 365 Audit | Initial Access |
| Analytics | Possible phishing attack via Microsoft Teams An external tenant is possibly attempting a phishing attack via Microsoft Teams. | Low | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible webshell file written by a web server process An uncommon file with a web file extension was created, written or renamed by a web server process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| Analytics BIOC | Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Collection, Initial Access |
| Analytics | Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. | Medium | Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log | Initial Access |
| Analytics BIOC | Potential spoofing of internal domain spotted An external sender is possibly impersonating an employee by spoofing the company's internal address. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion |
| Analytics BIOC | Quarantined email released to recipients This message was previously quarantined by vendor and has now been released and delivered to the intended recipients. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Rare MS-Update Server was detected The endpoint requested an MS-Update operation from a rare update server. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Rarely seen sender address in the organization An email was received from a sender that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Rarely seen sender domain in the organization An email was received from a domain that has not been observed in the organization in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Initial Access |
| Analytics BIOC | Sending unusual file(s) to an external address Unusual files sent to an external address. | Low | Email Security | Microsoft 365 Emails | Initial Access, Exfiltration |
| Analytics BIOC | SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a machine account A machine account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a service account A service account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO with abnormal operating system A user successfully authenticated via SSO with an abnormal operating system. | Informational | Identity Analytics | AzureAD, Okta, OneLogin | Initial Access |
| Analytics BIOC | SSO with abnormal user agent A user successfully authenticated via SSO with an abnormal user agent. | Informational | Identity Analytics | Okta, AzureAD, Azure SignIn Log, Duo, PingOne | Initial Access |
| Analytics BIOC | SSO with new operating system A user successfully authenticated via SSO with a new operating system. | Informational | Identity Analytics | Okta, Azure SignIn Log, AzureAD, Duo | Initial Access |
| Analytics BIOC | Successful universal authentication with suspicious features A universal authentication was flagged as suspicious based on anomalous features. | Informational | Identity Analytics | Initial Access | |
| BIOC | SunBurst Module loaded Sunburst malware hash loaded into SolarWinds.BusinessLayerHost.exe. | High | Platform Analytics | Module | Initial Access, Command and Control |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics BIOC | Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. | Medium | Identity Analytics | AzureAD | Initial Access, Defense Evasion |
| Analytics BIOC | Suspicious Azure AD interactive sign-in using PowerShell A user interactively logged in to Azure AD via PowerShell. | Informational | Identity Analytics | AzureAD | Initial Access |
| Analytics BIOC | Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious failed HTTP request - potential Spring4Shell exploit A potentially malicious failed HTTP request was received, possibly as part of a Spring4Shell exploitation attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access |
| Analytics BIOC | Suspicious heavy allocation of compute resources - possible mining activity An identity allocated an unusual heavy compute resource, suspected as mining activity. Heavy machines normally have a high amount of CPU cores or attached with GPU, which are targeted by adversaries to mine Cryptocurrency. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact, Initial Access |
| Analytics BIOC | Suspicious HTTP parameters detected The endpoint received suspicious HTTP parameters via an HTTP request, which may indicate attempts to exploit server components or web shell activity. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Initial Access, Persistence |
| Analytics BIOC | Suspicious MFA request reported by user in Entra ID A user has flagged an MFA request as suspicious in Microsoft Entra ID. This could indicate a potential compromised user account or unauthorized access attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Initial Access |
| Analytics BIOC | Suspicious Process Spawned by Adobe Reader Unusual process spawned by Adobe Reader with an uncommon command line. | Low | Platform Analytics | XDR Agent | Initial Access |
| Analytics | Suspicious sender exhibiting automated sending patterns Multiple messages from a single sender were observed over a short period, all having the same subject and differing body content. This repetitive pattern may indicate automated or scripted behavior. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics | Suspicious sending domain with sender address randomization Multiple messages from a single sender domain were observed over a short period, each using a unique sender address. This per-message sender randomization is uncommon for legitimate senders and suggests automated behavior. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Suspicious SSO access from ASN A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Suspicious SSO authentication A suspicious SSO authentication was made by a user. | Informational | Identity Analytics | Okta | Initial Access |
| Analytics BIOC | Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Training simulation email detected This email was flagged as part of a training simulation. | Low | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Uncommon URL domain(s) in your organization detected in email We have identified unpopular domain(s) in URL(s) within this email. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unique client computer model was detected via MS-Update protocol A unique client computer model was detected via MS-Update protocol. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access |
| Analytics BIOC | Unrecognized internal address (AAD mismatch) An email was received from an address using an internal domain, but the sender is not found in Active Directory. This may indicate an impersonation attempt or domain spoofing. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Unusual AWS Bedrock model access request A cloud identity requested access to an AWS Bedrock model. MITRE ATLAS Technique: AML.T0012 - Valid Accounts. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual cross projects activity A suspicious activity between different cloud projects. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Unusual DB process spawning a shell A DB related process abnormally spawned a shell. This might indicate an exploitation attempt. | Informational | Platform Analytics | XDR Agent | Initial Access, Lateral Movement |
| Analytics BIOC | Unusual display name in From header An email was detected with an unusual display name in the From header. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Unusual file-sharing links for mailbox owner The email contains unusual file-sharing link(s) for mailbox owner. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Unusual Process Spawned by Nginx in Ingress-Nginx pod Unusual Process Spawned by Nginx in Ingress-Nginx pod. | Low | Platform Analytics | XDR Agent | Execution, Initial Access |
| Analytics BIOC | Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |
| Analytics | Upload pattern that resembles Peer to Peer traffic A possible P2P protocol was spotted from an internal host. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Initial Access |
| Analytics BIOC | User signed in to an application via Power Automate for the first time A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Exfiltration |
| Analytics BIOC | VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login attempt by a honey user A VPN login attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login by a service account A service account attempted to log in to a VPN service. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login with a machine account A machine account successfully logged in to a VPN service. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |
| BIOC | Web server process drops an executable to disk Web server processes should not normally write executable files out to the local filesystem. This may have legitimate uses in certain web applications, yet check for possible exploitation of the hosted web application. | Informational | Platform Analytics | File | Initial Access |
| BIOC | Web server spawns an unsigned process Web server processes should normally only carry out tasks related to serving web applications. This instance has spawned an unsigned process, which may indicate a successful exploitation attempt of the associated web application. | Informational | Platform Analytics | Process execution | Initial Access |
| Analytics BIOC | X-Forefront-Antispam-Report has flagged this email as a potential threat This email has been categorized by X-Forefront-Antispam-Report as a threat, suggesting it is likely malicious in nature (e.g., spam, phishing, impersonation, etc.). | Informational | Email Security | Microsoft 365 Emails | Initial Access, Defense Evasion, Execution |