Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1061 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Azure user creation/deletion A user in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure user password reset The password of an Azure AD user was reset. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. | Informational | Cortex Cloud | Azure Audit Log | Execution, Lateral Movement |
| Analytics BIOC | Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. | Informational | Cortex Cloud | Azure Audit Log | Execution, Persistence, Defense Evasion |
| Analytics BIOC | Bedrock model shared with a foreign account A bedrock model was shared with a foreign account through AWS resource access manager. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | Billing admin role was removed Sensitive Action - Billing admin role was removed. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | BitLocker key retrieval An identity retrieved a BitLocker Key. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. | Medium | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Broker Collection Error A collection error was detected on a broker VM. | Informational | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. | High | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Browser Extension Installed Uncommon browser extension installed. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Bucket's block public access setting turned off S3 bucket block public access setting turned off. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Certutil pfx parsing Certutil was used to parse a pfx certificate file. | Low | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Privilege Escalation |
| Analytics BIOC | Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Initial Access, Persistence |
| Analytics BIOC | Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Lateral Movement |
| Analytics BIOC | ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Initial Access |
| Analytics BIOC | Cloud access key creation Cloud access key creation by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Command and Control |
| Analytics BIOC | Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud compute instance user data script modification The user data of a cloud compute instance was modified. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Execution |
| Analytics BIOC | Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Lateral Movement |
| Analytics BIOC | Cloud compute volume creation attempt An attempt was made to create an EBS volume. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Collection |
| Analytics BIOC | Cloud email sending was enabled Cloud email sending was enabled for the cloud account. | Informational | Cortex Cloud | AWS Audit Log | Resource Development |
| Analytics BIOC | Cloud email service activity A cloud Identity performed an email service operation. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Lateral Movement |
| Analytics BIOC | Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | Cloud instance creation attempt An attempt was made to create a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs | Execution |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. | Medium | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | Cloud Watch alarm deletion A Cloud Watch alarm was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | CloudTrail logging deletion CloudTrail logging trail deletion. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Collection error A collection error was detected. | High | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command execution via wmiexec Attackers may use WMI to execute commands on the target host. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. | Medium | Platform Analytics | XDR Agent | Exfiltration, Execution |
| Analytics BIOC | Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution |
| Analytics BIOC | Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. | Informational | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Compressing data using python Usage of a Python module to compress files. | Low | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Conditional Access policy removed An identity removed a Conditional Access policy. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Correlation rule error An error was identified while running a correlation rule. | Medium | Platform Analytics | Health Monitoring Data | Impact |
| Analytics BIOC | Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Credentials were added to Azure application Credentials were added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | Data encryption was disabled A cloud identity has disabled data encryption. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Impact |
| Analytics BIOC | Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution |
| Analytics BIOC | Device Registration Policy modification An identity changed the Device Registration policy. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion |
| Analytics BIOC | Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. | Low | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Display text URL differs from actual URL An email contains a hyperlink whose display text shows a URL different from the actual destination URL. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Download a script using the python requests module Download a shell script from a remote location using the Python requests module. | Low | Platform Analytics | XDR Agent | Execution |
| Analytics BIOC | DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Execution |
| Analytics BIOC | EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| Analytics BIOC | EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Elevation to SYSTEM via services Services were affected by a non SYSTEM integrity level process. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Privilege Escalation |
| Analytics BIOC | Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. | Informational | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. | Informational | Email Security | Microsoft 365 Emails | Execution, Defense Evasion |
| Analytics BIOC | Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. | Low | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email containing a redirected link An email with a redirected link has been detected. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion, Execution |
| Analytics BIOC | Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email mimics replies or forwards without an actual ongoing conversation An email with a subject line or body that includes signs of a reply or forward without an actual ongoing conversation. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Email sent using an automated system or script detected The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. | Informational | Email Security | Microsoft 365 Emails | Initial Access |
| Analytics BIOC | Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. | Informational | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email was received from an unknown sender using a disposable domain The email was received from an unknown sender using a disposable email provider, first seen in the organization in the past month. | Low | Email Security | Microsoft 365 Emails | Reconnaissance, Initial Access |
| Analytics BIOC | Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. | Low | Email Security | Microsoft 365 Emails | Initial Access, Execution |
| Analytics BIOC | Email with URL shortener detected A URL shortener was detected in the email body. | Informational | Email Security | Microsoft 365 Emails | Defense Evasion |
| Analytics BIOC | Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. | Medium | Platform Analytics | XDR Agent | Defense Evasion |