Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1677 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Impact |
| Analytics BIOC | An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | An AWS Lambda Function was created An AWS Lambda Function was created. | Informational | Cortex Cloud | AWS Audit Log | Execution, Persistence |
| Analytics BIOC | An AWS Lambda function was modified An AWS Lambda function was modified. | Informational | Cortex Cloud | AWS Audit Log | Execution |
| Analytics BIOC | An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS Route 53 domain was transferred to another AWS account An AWS Route 53 domain was transferred to another AWS account. | Informational | Cortex Cloud | AWS Audit Log | Resource Development |
| Analytics BIOC | An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Impact |
| Analytics BIOC | An AWS SAML provider was modified An AWS SAML provider was modified. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Defense Evasion |
| Analytics BIOC | An AWS SES identity was deleted An AWS SES identity has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An Azure application reached a throttling API rate An Azure application has executed a high volume of Microsoft Graph API calls, causing a throttling error. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | An Azure DNS Zone was modified An Azure DNS zone has been changed or removed, which may indicate malicious activity or a misconfiguration. | Informational | Cortex Cloud | Azure Audit Log | Command and Control |
| Analytics BIOC | An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics | An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | An Azure Key Vault key was modified An Azure Key Vault key was modified. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An Azure Key Vault was modified Azure Key Vault has been modified or deleted by an Identity. This could be an indication of unauthorized access or malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure Kubernetes Role or Cluster-Role was modified An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted. This could indicate a security breach or malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure SQL database was exported from a production subscription An Azure SQL database export was initiated. The database was exported from a production subscription. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure Suppression Rule was created An Azure Suppression Rule was created. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure virtual network Device was modified An Azure virtual network Device was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure virtual network was modified An Azure virtual network has been modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated for export from a production subscription A SAS URL for an Azure VM snapshot was generated. The operation was performed within a production subscription. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An Email address was added to AWS SES An Email address was added to AWS SES. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| BIOC | An executable compiled with a py2exe-like program was executed A py2exe-like program DLL file dropped to disk. | Informational | Platform Analytics | File | Execution |
| Analytics | An executable was written and executed by a web server Web server process had written an executable file that was executed shortly after. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An IAM group was created An IAM group was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed Azure Kubernetes Secrets An identity has accessed or attempted to access Azure Kubernetes secrets or Config Objects. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity disabled bucket logging An identity disabled bucket logging. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity started an AWS SSM session An identity started an AWS SSM interactive session. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics | An identity successfully extracted multiple secrets within the organization An identity successfully dumped multiple secrets from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | An inactive user attempted to authenticate A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. | Informational | Identity Analytics | Initial Access | |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown S3 bucket An RDS snapshot was exported to an S3 bucket. The destination S3 bucket was not seen in your organization in the last 30 days. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An uncommon executable was remotely written over SMB to an uncommon destination An uncommon executable was remotely written over SMB to a destination, which was not involved in significant similar activity during last month. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement |
| Analytics BIOC | An uncommon file added to startup-related Registry keys An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An uncommon file was created in the startup folder An uncommon file was created in the startup folder. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon RDP session was established An RDP session was established with uncommon parameters. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon service was started An uncommon service was started using systemctl or service processes. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation |
| Analytics BIOC | An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. | Medium | Platform Analytics | XDR Agent | Persistence, Defense Evasion |
| Analytics BIOC | An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration, Defense Evasion |
| Analytics | An unusual process in ingress-nginx has accessed a service-account token file An unusual process in ingress-nginx has read a service-account token. | High | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Credential Access |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. | Informational | Platform Analytics | Palo Alto Networks Firewall threat Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Initial Access |
| Analytics BIOC | Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Authentication method added to an Azure account An identity attempted to add an Azure authentication method. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Authentication method was added to Azure account A new authentication method was added to an Azure AD user. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. | Medium | Platform Analytics | XDR Agent | Persistence, Lateral Movement |
| Analytics BIOC | AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |