Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

42 detectors match the current filters. tactic: TA0004 ✕ technique: T1098 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Privilege Escalation
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. Informational Identity Analytics XDR Agent Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user was added to a Windows security group A user was added to a Windows security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC External user invitation to Azure tenant An external user was invited to Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP set IAM policy activity A cloud identity had modified a resource policy bindings. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was created An AWS IAM instance profile was created. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy version was created A cloud identity created an AWS-managed IAM policy version. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to role An AWS IAM policy was attached to this role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM role was created An IAM role was created. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC Member added to a Windows local security group A member was added to a Windows local security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Okta admin privilege assignment A user assigned admin privileges to a new user or group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation
Analytics BIOC Okta API Token Created A user created a new API token in Okta. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Privilege Escalation, Execution, Persistence
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
Analytics Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence, Privilege Escalation
Analytics User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation