Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1061 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC An uncommon file was created in the startup folder An uncommon file was created in the startup folder. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon RDP session was established An RDP session was established with uncommon parameters. Informational Platform Analytics XDR Agent Lateral Movement
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. Informational Cortex Cloud Gcp Audit Log Exfiltration, Defense Evasion
Analytics BIOC An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. Informational Platform Analytics Palo Alto Networks Firewall threat Logs, XDR Agent Reconnaissance
Analytics BIOC AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. Informational Platform Analytics XDR Agent Execution
Analytics BIOC AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. Low Platform Analytics XDR Agent Lateral Movement, Execution
Analytics BIOC Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Initial Access
Analytics BIOC Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC Authentication method added to an Azure account An identity attempted to add an Azure authentication method. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Authentication method was added to Azure account A new authentication method was added to an Azure AD user. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
Analytics BIOC AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS data asset shared public A data asset was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS root account activity The AWS root account has successfully performed an operation in the project. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. Low Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SecurityHub findings were modified AWS SecurityHub findings were modified. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access
Analytics BIOC AWS SSM send command attempt An identity executed an AWS SSM Document. Informational Cortex Cloud AWS Audit Log Lateral Movement, Execution
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS user creation A new AWS user was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure account deletion by a non-standard account An Azure AD account deletion was performed by a user that doesn't typically delete users. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Impact
Analytics BIOC Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. Medium Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure AD PIM role settings change An identity changed the PIM role settings. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure application consent An identity consented permissions to an application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access, Credential Access
Analytics BIOC Azure application credentials added An identity added credentials to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure application removed An Azure application has been deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure application URI modification An identity added or updated an Azure application's URI. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure conditional access policy creation or modification An Azure conditional access policy was created or modified. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Defense Evasion
Analytics BIOC Azure device code authentication flow used An Azure AD login was performed with device code flow. Informational Identity Analytics Azure Audit Log Defense Evasion, Persistence
Analytics BIOC Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Privilege Escalation
Analytics BIOC Azure Event Hub Authorization rule creation/modification An authorization rule is bound with specific rights, once created within a namespace, which has management permissions. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure group creation/deletion A group in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure mailbox rule creation A Mailbox rule in Azure was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection, Defense Evasion
Analytics BIOC Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion, Execution
Analytics BIOC Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. Low Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure permission delegation granted An identity delegated permissions to access a certain resource or application. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. Informational Cortex Cloud Azure Audit Log Defense Evasion, Lateral Movement
Analytics BIOC Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure Service principal/Application creation An Azure Service principal/Application was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access