Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
5 detectors match the current filters. tactic: TA0001 ✕ technique: T1133 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An operation was performed by an identity from a domain that was not seen in the organization An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access |
| Analytics BIOC | SaaS suspicious external domain user activity An operation was performed by an identity. This identity belongs to a domain that was not seen in the organization before. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Initial Access |
| Analytics BIOC | Suspicious External RDP Login An unusual successful RDP connection by a user from an external IP. This may be indicative of using stolen credentials or malicious activity. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Suspicious successful RDP connection to localhost An unusual process created a successful RDP connection to localhost. This may indicate the use of a tunnel to bypass a firewall. | Informational | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Web server CGO executed an uncommon process An uncommon process was executed by a web server CGO, which might indicate a Webshell activity or a web server exploit. | Informational | Platform Analytics | XDR Agent | Initial Access, Persistence |