Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
7 detectors match the current filters. technique: T1090 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Successful login from TOR A successful login from a TOR exit node. | High | Identity Analytics | XDR Agent | Initial Access, Command and Control |
| Analytics BIOC | A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. | High | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Command and Control |
| Analytics BIOC | A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. | High | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access, Command and Control |
| Analytics BIOC | Netcat makes or gets connections Malicious actors can use Netcat for privilege escalation, remote code execution, data exfiltration and protocol tunneling to evade detection. | High | Platform Analytics | XDR Agent | Command and Control |
| Analytics BIOC | Suspicious AI model usage from a Tor exit node A cloud identity invoked an AI model from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Command and Control |
| Analytics BIOC | Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. | High | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Command and Control, Initial Access |
| Analytics BIOC | Suspicious SaaS API call from a Tor exit node A SaaS API was called from a Tor exit node. | High | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Command and Control |