Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1061 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An uncommon file was created in the startup folder An uncommon file was created in the startup folder. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. | Informational | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | An uncommon RDP session from a managed host An RDP session was established with uncommon parameters from a managed host. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon RDP session was established An RDP session was established with uncommon parameters. | Informational | Platform Analytics | XDR Agent | Lateral Movement |
| Analytics BIOC | An uncommon service was started An uncommon service was started using systemctl or service processes. | Low | Platform Analytics | XDR Agent | Persistence, Privilege Escalation |
| Analytics BIOC | An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | An unpopular process accessed the microphone on the host An unpopular process accessed the microphone on the host, the process can abuse this device. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration, Defense Evasion |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Analytics enhanced NGFW Threat Alert - Rare Internal Firewall Vulnerability Threat Alert An internal host triggered an NGFW (Next-Generation Firewall) vulnerability threat alert targeting another internal host. This activity is highly anomalous as it deviates from the source host's historical behavior and is rarely seen targeting this specific destination across the organization. | Informational | Platform Analytics | Palo Alto Networks Firewall threat Logs, XDR Agent | Reconnaissance |
| Analytics BIOC | AppleScript executed a shell script An uncommon shell script has been executed by the AppleScript interpreter process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript interpreter dynamic library loaded into a process The AppleScript interpreter dynamic library was loaded into a process. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | AppleScript process executed with a rare command line The AppleScript interpreter process was executed with an uncommon command line. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Attempt to execute a command on a remote host using PsExec.exe There was an attempt to run a command on a remote host using PsExec.exe. | Low | Platform Analytics | XDR Agent | Lateral Movement, Execution |
| Analytics BIOC | Attempted Azure application access from unknown tenant A Microsoft Graph API was unsuccessfully executed by an Azure application from an unknown tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Initial Access |
| Analytics BIOC | Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Defense Evasion |
| Analytics BIOC | Authentication method added to an Azure account An identity attempted to add an Azure authentication method. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Authentication method was added to Azure account A new authentication method was added to an Azure AD user. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. | Medium | Platform Analytics | XDR Agent | Persistence, Lateral Movement |
| Analytics BIOC | AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| Analytics BIOC | AWS network ACL rule deletion An AWS network ACL rule was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS principals discovery A cloud identity has enumerated principals. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | AWS resource discovery A cloud identity has enumerated resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS root account activity The AWS root account has successfully performed an operation in the project. | Informational | Cortex Cloud | AWS Audit Log | Initial Access |
| Analytics BIOC | AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS SecurityHub findings were modified AWS SecurityHub findings were modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS SES account sending settings modified AWS SES account sending settings were modified. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Execution |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS SSM send command attempt An identity executed an AWS SSM Document. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement, Execution |
| Analytics BIOC | AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS user creation A new AWS user was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure account deletion by a non-standard account An Azure AD account deletion was performed by a user that doesn't typically delete users. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Impact |
| Analytics BIOC | Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure AD PIM alert disabled An identity disabled an Azure AD PIM alert. | Medium | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure AD PIM role settings change An identity changed the PIM role settings. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application removed An Azure application has been deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Impact |
| Analytics BIOC | Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure conditional access policy creation or modification An Azure conditional access policy was created or modified. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Defense Evasion |
| Analytics BIOC | Azure device code authentication flow used An Azure AD login was performed with device code flow. | Informational | Identity Analytics | Azure Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Azure Event Hub Authorization rule creation/modification An authorization rule is bound with specific rights, once created within a namespace, which has management permissions. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure group creation/deletion A group in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure mailbox rule creation A Mailbox rule in Azure was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection, Defense Evasion |
| Analytics BIOC | Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Execution |
| Analytics BIOC | Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure permission delegation granted An identity delegated permissions to access a certain resource or application. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Azure route table creation or modification An Azure route table, or one of its individual routes, was created or modified. Azure route tables control how traffic flows between subnets and virtual networks. Adversaries can tamper with route tables to redirect traffic to attacker-controlled destinations, bypassing security appliances or enabling man-in-the-middle attacks. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Lateral Movement |
| Analytics BIOC | Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure Service principal/Application creation An Azure Service principal/Application was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |