Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
96 detectors match the current filters. tactic: TA0004 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A Google Workspace service was configured as unrestricted An identity configured a Google Workspace service as unrestricted Apps configured with a trusted or limited access setting can access data for unrestricted services. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Privilege Escalation |
| Analytics BIOC | A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Initial Access, Privilege Escalation |
| Analytics BIOC | A user accessed Okta's admin application An attempt to access Okta's admin management application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence, Privilege Escalation |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics | A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user was added to a Windows security group A user was added to a Windows security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | A WMI subscriber was created A WMI subscriber was created. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics | Abnormal File Activity in SCCMContentLib Shared Folder by user A user generated suspicious file activity within the SCCMContentLib shared folder, which is considered a high-value target for attackers. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Privilege Escalation |
| Analytics BIOC | Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. | Informational | Identity Analytics | XDR Agent | Lateral Movement, Privilege Escalation |
| Analytics BIOC | Access to sensitive host files from within a Kubernetes pod A process accessed sensitive host files inside a Kubernetes pod, indicating a potential container escape or privilege escalation attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Admin privileges were granted to a Google Workspace user Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | An Azure Kubernetes Role or Cluster-Role was modified An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted. This could indicate a security breach or malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. | Informational | Cortex Cloud | Azure Audit Log | Privilege Escalation |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Privilege Escalation |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Privilege Escalation |
| BIOC | Bypassing Windows UAC using sysprep Attackers may use the sysprep.exe built-in Windows tools to bypass Windows UAC. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Command enumeration via sudo The 'sudo -l' command was executed to enumerate commands that can be executed by a user. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Creation or modification of the default command executed when opening an application Creation or modification of these registry keys can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Credentials were added to Azure application Credentials were added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| BIOC | Discovery of files with setgid or setuid bits Attackers may try to locate files with setgid or setuid bits set to escalate privileges. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | External user invitation to Azure tenant An external user was invited to Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. | Informational | Cortex Cloud | Gcp Audit Log | Privilege Escalation, Initial Access |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Gmail delegation was turned on for the organization A Google Workspace admin turned on Gmail delegation for all the organization's users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Google Marketplace restrictions were modified An identity modified Google Marketplace Restrictions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | Google Workspace third-party application's security settings were changed An identity changed Google Workspace third-party application's security settings. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was created An AWS IAM instance profile was created. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy version was created A cloud identity created an AWS-managed IAM policy version. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to role An AWS IAM policy was attached to this role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM User added to an IAM group An IAM user was added to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. | Informational | Platform Analytics | XDR Agent | Privilege Escalation, Discovery |
| Analytics BIOC | Kubernetes nsenter container escape The nsenter command was used to execute a process in the context of the initialization process. | Informational | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Kubernetes Pod Created with host Inter Process Communications (IPC) namespace An identity created a Kubernetes pod with the host Inter Process Communications (IPC) namespace. This may indicate an adversary attempting to access data used by other pods that use the host's IPC namespace. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| Analytics BIOC | Kubernetes Pod created with host process ID (PID) namespace An identity created a Kubernetes pod with the host process ID (PID) namespace. This may indicate an adversary attempting to access processes running on the host, which could allow escalating privileges to root. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| Analytics BIOC | Kubernetes Pod Created With Sensitive Volume An identity created a Kubernetes Pod with a sensitive volume, allowing the Pod to have read or write permissions on the host's filesystem This could suggest an effort by an adversary to access sensitive files on the host and employ techniques for escalating privileges. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| Analytics BIOC | Kubernetes pod creation with host network An identity created a Kubernetes pod attached to the host network. This may indicate an adversary attempting to access services bound to localhost, sniff traffic on any interface on the host, and potentially bypass the network policy. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| Analytics BIOC | Kubernetes Privileged Pod Creation An identity created a Kubernetes pod with a privileged container. This may indicate an adversary attempting to access that host's filesystem or gain root access to the host. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation, Execution |
| BIOC | Manipulation of MMC Registry configuration Creation or modification of these Microsoft Management Console related entries can cause the execution of the specified programs, bypassing UAC. | Informational | Platform Analytics | Registry | Privilege Escalation |
| Analytics BIOC | Member added to a Windows local security group A member was added to a Windows local security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics | Microsoft Configuration Manager device registration and policy request A user registered a device and requested a Microsoft Configuration Manager policy. | Informational | Identity Analytics | XDR Agent | Credential Access, Privilege Escalation |
| BIOC | Modifying ELF file capabilities via setcap An attacker may attempt to gain privileges by setting the capabilities of a file. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics | Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Okta admin privilege assignment A user assigned admin privileges to a new user or group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation |
| Analytics BIOC | Okta API Token Created A user created a new API token in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation, Execution, Persistence |
| Analytics BIOC | Owner was added to Azure application An Owner was added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Privilege Escalation, Persistence |
| Analytics BIOC | PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Lateral Movement, Privilege Escalation |
| Analytics BIOC | Possible DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. This DLL name is usually signed by Microsoft, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics | Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Privileged certificate request via certificate template A privileged certificate was requested via certificate template. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| BIOC | PsExec runs with System privileges PsExec.exe is a Windows administrative tool, it can be used to elevate privileges and run other processes with NT/System privilege level. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | PsExec was executed with a suspicious command line PsExec.exe was executed. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| BIOC | Security Support Provider (SSP) registered via a registry key Security Support Provider (SSP) exposes a number of callbacks to be invoked during certain authentication and authorization events. An attacker may register SSP to try and gain access to clear text passwords. | Informational | Platform Analytics | Registry | Privilege Escalation |
| BIOC | Setuid on file Setting user identification on an executable file causes it to run with the privileges of the owning user. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| BIOC | Shim database file access An attacker may install a malicious SDB (shim database) file on disk for privilege escalation and persistence. | Informational | Platform Analytics | File | Persistence, Privilege Escalation |
| BIOC | Sudoers discovery Attackers may enumerate the sudoers file or use the 'sudo -l' command to discover user privileges. | Informational | Platform Analytics | Process execution | Discovery, Privilege Escalation |
| Analytics BIOC | Suspicious process executed with a high integrity level A suspicious process was spawned with a High or System integrity level, which is higher than its parent process. This may indicate malicious privilege escalation. | Informational | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics BIOC | Suspicious process execution in a privileged container A process was executed in a privileged Kubernetes Pod for the first time in the past 30 days. | Informational | Platform Analytics | XDR Agent | Execution, Privilege Escalation |
| Analytics BIOC | Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Unsigned DLL Hijack into a Microsoft process An unsigned DLL was loaded into a Microsoft signed process. It is not common for the DLL to be loaded into Microsoft processes, which might indicate an attacker performing DLL Hijacking. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unsigned DLL Side-Loading A signed process loaded an unsigned and rare module from the same folder. | Informational | Platform Analytics | XDR Agent | Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | Unusual cloud identity impersonation A cloud identity attempted to impersonate another identity for the first time. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Privilege Escalation, Defense Evasion, Initial Access |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| BIOC | Unusual process spawned by changepk.exe Attackers may use the changepk.exe built-in Windows tool to bypass UAC using an unusual initiator. | Informational | Platform Analytics | Process execution | Privilege Escalation |
| Analytics BIOC | Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Privilege Escalation, Impact |
| Analytics BIOC | Unusual user-agent for a cloud identity A cloud identity has executed an API call with an unusual user-agent. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Initial Access, Persistence, Privilege Escalation, Defense Evasion |
| Analytics BIOC | User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Defense Evasion |
| Analytics | User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |