Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1088 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration, Defense Evasion |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. | Informational | Platform Analytics | Palo Alto Networks Firewall threat Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Initial Access |
| Analytics BIOC | Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Authentication method added to an Azure account An identity attempted to add an Azure authentication method. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Authentication method was added to Azure account A new authentication method was added to an Azure AD user. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics | AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics | AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| Analytics BIOC | AWS network ACL rule deletion An AWS network ACL rule was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS principals discovery A cloud identity has enumerated principals. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS resource discovery A cloud identity has enumerated resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS root account activity The AWS root account has successfully performed an operation in the project. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics | AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics | AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS SecurityHub findings were modified AWS SecurityHub findings were modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS SES account sending settings modified AWS SES account sending settings were modified. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Execution |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS SSM send command attempt An identity executed an AWS SSM Document. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement, Execution |
| Analytics BIOC | AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS user creation A new AWS user was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application removed An Azure application has been deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Impact |
| Analytics BIOC | Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure conditional access policy creation or modification An Azure conditional access policy was created or modified. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Defense Evasion |
| Analytics BIOC | Azure device code authentication flow used An Azure AD login was performed with device code flow. | Informational | Identity Analytics | Azure Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics | Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Azure Event Hub Authorization rule creation/modification An authorization rule is bound with specific rights, once created within a namespace, which has management permissions. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure group creation/deletion A group in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure mailbox rule creation A Mailbox rule in Azure was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection, Defense Evasion |
| Analytics BIOC | Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Execution |
| Analytics BIOC | Azure permission delegation granted An identity delegated permissions to access a certain resource or application. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Lateral Movement |
| Analytics BIOC | Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure Service principal/Application creation An Azure Service principal/Application was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure user creation/deletion A user in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure user password reset The password of an Azure AD user was reset. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. | Informational | Cortex Cloud | Azure Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. | Informational | Cortex Cloud | Azure Audit Log | Execution, Persistence, Defense Evasion |
| BIOC | Base64 decoding using the base64 utility Base64 decoding using the base64 utility with the -d argument provided. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Base64 encoding used Attackers may use the base64 built-in binary to encode data into base64. | Informational | Platform Analytics | Process execution | Command and Control |
| Analytics BIOC | BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | BitLocker key retrieval An identity retrieved a BitLocker Key. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| BIOC | Bitsadmin.exe used to download data Some attacks were known for abusing BITSAdmin in the past to hide how data was downloaded using legitimate Windows tools. | Informational | Platform Analytics | Process execution | Persistence |
| BIOC | BitTorrent P2P file sharing The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information. | Informational | Platform Analytics | Dml connection | Exfiltration |
| Analytics BIOC | Broker Collection Error A collection error was detected on a broker VM. | Informational | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | Browser downloads an .hta or .application file .hta and .application files are Windows applications that may serve as an attack vector by executing code maliciously using trusted Windows applications. | Informational | Platform Analytics | File | Defense Evasion |
| Analytics BIOC | Browser Extension Installed Uncommon browser extension installed. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |