Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

1061 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure user creation/deletion A user in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure user password reset The password of an Azure AD user was reset. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure virtual machine commands execution An Azure virtual machine executed PowerShell commands with System privileges. Informational Cortex Cloud Azure Audit Log Execution, Lateral Movement
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
Analytics BIOC Bedrock model shared with a foreign account A bedrock model was shared with a foreign account through AWS resource access manager. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC Billing admin role was removed Sensitive Action - Billing admin role was removed. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC BitLocker key retrieval An identity retrieved a BitLocker Key. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Broker Collection Error A collection error was detected on a broker VM. Informational Platform Analytics Health Monitoring Data Impact
Analytics BIOC Bronze-Bit exploit A forwardable Kerberos ticket for delegation of a Protected User was observed. High Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Browser Extension Installed Uncommon browser extension installed. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Bucket's block public access setting turned off S3 bucket block public access setting turned off. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. Low Platform Analytics XDR Agent Credential Access, Discovery
Analytics BIOC Certutil pfx parsing Certutil was used to parse a pfx certificate file. Low Platform Analytics XDR Agent Collection
Analytics BIOC Change of sudo caching configuration Change of sudo caching configuration may have been intended to enable privilege escalation. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Privilege Escalation
Analytics BIOC Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Persistence
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
Analytics BIOC ClickFix - PowerShell executed through the run application An attacker may be trying to trick a user to execute PowerShell through the run application. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Initial Access
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud compute instance user data script modification The user data of a cloud compute instance was modified. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Execution
Analytics BIOC Cloud compute serial console access An identity connected to a compute instance using serial console access. This may indicate an attacker attempting to move laterally between cloud instances. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Lateral Movement
Analytics BIOC Cloud compute volume creation attempt An attempt was made to create an EBS volume. Informational Cortex Cloud AWS Audit Log Defense Evasion, Collection
Analytics BIOC Cloud email sending was enabled Cloud email sending was enabled for the cloud account. Informational Cortex Cloud AWS Audit Log Resource Development
Analytics BIOC Cloud email service activity A cloud Identity performed an email service operation. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Lateral Movement
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Cloud instance creation attempt An attempt was made to create a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud instance deletion attempt An attempt was made to delete a cloud compute instance. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Cloud penetration testing tool activity A cloud API was successfully executed using a known cloud penetration testing tool. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Microsoft Graph Logs Execution
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. Medium Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Collection error A collection error was detected. High Platform Analytics Health Monitoring Data Impact
Analytics BIOC Command execution in a Kubernetes pod Container administration commands were executed within a Kubernetes pod. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command execution via wmiexec Attackers may use WMI to execute commands on the target host. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Command running with COMSPEC in the command line argument COMSPEC is an environmental variable that points to cmd.exe. Attackers may use this command to obfuscate their command and avoid detection. Low Platform Analytics XDR Agent Execution
Analytics BIOC Common third-party software name masquerading An attacker might leverage common third-party software image names to run malicious processes without being caught. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC Commonly abused AutoIT script drops an executable file to disk AutoIT scripts have legitimate uses but are often abused by malware to execute in a signed process context. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution
Analytics BIOC Commonly abused process launched as a system service This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism. Informational Platform Analytics XDR Agent Execution
Analytics BIOC Compressing data using python Usage of a Python module to compress files. Low Platform Analytics XDR Agent Collection
Analytics BIOC Compute activity in dormant cloud region A compute resource was created or updated in a cloud region that has been dormant for this project. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Conditional Access policy removed An identity removed a Conditional Access policy. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Conhost.exe spawned a suspicious cmd process Attackers may abuse the conhost process to execute malicious files and evade detection. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Contained process execution with a rare GitHub URL A contained process was executed with a suspicious GitHub url in the command line. This may be a legitimate use, but this technique is frequently used by attackers to download malicious payloads. Low Platform Analytics XDR Agent Execution
Analytics BIOC Copy a process memory file Copy a process memory file using the dd utility. High Platform Analytics XDR Agent Credential Access
Analytics BIOC Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Correlation rule error An error was identified while running a correlation rule. Medium Platform Analytics Health Monitoring Data Impact
Analytics BIOC Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Impact
Analytics BIOC Delayed Deletion of Files A command line deleting files used the time-out or ping commands to delay the file deletion. This is suspicious, as malware sometimes uses these techniques to cover their tracks. Low Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Denied API call by a Kubernetes service account A Kubernetes service account API call was denied. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Execution
Analytics BIOC Device Registration Policy modification An identity changed the Device Registration policy. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Disable encryption operations Encryption was disabled on the servers that host EC2 instances, both for data-at-rest and data-in-transit. Low Cortex Cloud AWS Audit Log Impact
Analytics BIOC Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. Low Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics BIOC Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Display text URL differs from actual URL An email contains a hyperlink whose display text shows a URL different from the actual destination URL. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Download a script using the python requests module Download a shell script from a remote location using the Python requests module. Low Platform Analytics XDR Agent Execution
Analytics BIOC DSC (Desired State Configuration) lateral movement using PowerShell An attacker is using the DSC feature with PowerShell to remotely modify / execute content / components on the machine. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Execution
Analytics BIOC EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. Informational Cortex Cloud AWS Audit Log Collection
Analytics BIOC EBS volume attachment attempt An attempt was made to attach an EBS volume to an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EBS volume detachment attempt An attempt was made to detach an AWS EBS volume from an EC2 instance. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Elevation to SYSTEM via services Services were affected by a non SYSTEM integrity level process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Privilege Escalation
Analytics BIOC Email attachment with a potentially malicious file extension The email message includes attachments with file types that are typically blocked by the email vendor as a precaution due to their suspicious nature. Informational Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Email attachment with multiple extensions The email includes an attachment(s) with two extensions. The first one being an executable extension. This may indicate an attempt at masquerading the true file type through the misuse of multiple extensions in the attachment name. Informational Email Security Microsoft 365 Emails Execution, Defense Evasion
Analytics BIOC Email attachment with Right-to-Left Override Unicode character The email message contains an attachment with a hidden Right-to-Left Override Unicode character. Low Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email attachment(s) with potentially malicious MIME type The email message contains an attachment(s) with a potentially malicious MIME type. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email containing a link with an IP address convention was detected A link with IP address convention was detected within the email body. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email containing a redirected link An email with a redirected link has been detected. Informational Email Security Microsoft 365 Emails Defense Evasion, Execution
Analytics BIOC Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. Informational Email Security Microsoft 365 Emails Execution, Credential Access
Analytics BIOC Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values The Spam Confidence Level (SCL) and Bulk Complaint Level (BCL) values, detected in the email's antispam headers, indicate that a message is more likely to be spam. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email mimics replies or forwards without an actual ongoing conversation An email with a subject line or body that includes signs of a reply or forward without an actual ongoing conversation. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email sent using an automated system or script detected The message contains X-PHP-Script or X-PHP-Originating-Script headers, indicating it was generated by an automated PHP script or web application. While often legitimate, this behavior is frequently associated with shared hosting abuse, phishing kits, and compromised web applications. Informational Email Security Microsoft 365 Emails Initial Access
Analytics BIOC Email was received from an unknown address using a public provider domain The email was received from an unknown address, that was seen for the first time in the organization in the past month, and registered under a public provider. Informational Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email was received from an unknown sender using a disposable domain The email was received from an unknown sender using a disposable email provider, first seen in the organization in the past month. Low Email Security Microsoft 365 Emails Reconnaissance, Initial Access
Analytics BIOC Email with file-sharing link containing auto-download parameter The email contains a link to a file-sharing service that includes parameters likely to trigger automatic download. Low Email Security Microsoft 365 Emails Initial Access, Execution
Analytics BIOC Email with URL shortener detected A URL shortener was detected in the email body. Informational Email Security Microsoft 365 Emails Defense Evasion
Analytics BIOC Encoded information using Windows certificate management tool Encoding/decoding to/from using certutil.exe could be used to evade detection. Medium Platform Analytics XDR Agent Defense Evasion