Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
42 detectors match the current filters. tactic: TA0004 ✕ technique: T1098 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A user accessed Okta's admin application An attempt to access Okta's admin management application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence, Privilege Escalation |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics | A user logged on to multiple workstations via Schannel A user logged on to multiple workstations with a certificate via Schannel. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user was added to a Windows security group A user was added to a Windows security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Credentials were added to Azure application Credentials were added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | External user invitation to Azure tenant An external user was invited to Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was created An AWS IAM instance profile was created. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy version was created A cloud identity created an AWS-managed IAM policy version. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to role An AWS IAM policy was attached to this role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM User added to an IAM group An IAM user was added to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | Member added to a Windows local security group A member was added to a Windows local security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | Okta admin privilege assignment A user assigned admin privileges to a new user or group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation |
| Analytics BIOC | Okta API Token Created A user created a new API token in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation, Execution, Persistence |
| Analytics BIOC | Owner was added to Azure application An Owner was added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Privilege Escalation, Persistence |
| Analytics | Possible Privilege Escalation using Delegated MSA account An attacker might abuse dMSA account to escalate its privileges. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics | User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |