Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

133 detectors match the current filters. tactic: TA0007 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics BIOC A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment A new server has been added to an Azure Active Directory Hybrid Health AD FS Environment. Informational Cortex Cloud Azure Audit Log Discovery
Analytics BIOC A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Discovery, Initial Access
Analytics BIOC A user changed the Windows system time A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine. Informational Identity Threat Detection (ITDR) Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery, Credential Access
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
BIOC Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. Informational Platform Analytics Process execution Discovery
BIOC ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). Informational Platform Analytics Process execution Discovery
Analytics BIOC Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. Informational Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC An Azure application reached a throttling API rate An Azure application has executed a high volume of Microsoft Graph API calls, causing a throttling error. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS principals discovery A cloud identity has enumerated principals. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS resource discovery A cloud identity has enumerated resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. Informational Cortex Cloud AWS Audit Log Discovery, Execution
Analytics BIOC AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. Informational Cortex Cloud AWS Audit Log Credential Access, Discovery
Analytics BIOC AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC AWS support case creation A cloud identity has created a new case in AWS support. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics BIOC AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics BIOC Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
BIOC Container enumeration An attacker may run a command to enumerate containers on a machine. Informational Platform Analytics Process execution Discovery
Analytics BIOC Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. Informational Platform Analytics XDR Agent Discovery
BIOC Document discovery Attackers may use the find command to look for documents. Informational Platform Analytics Process execution Discovery
BIOC Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. Informational Platform Analytics Process execution Discovery
BIOC Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. Informational Platform Analytics Process execution Discovery, Execution
BIOC Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. Informational Platform Analytics Dml connection Discovery
BIOC Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. Informational Platform Analytics Process execution Defense Evasion, Discovery
Analytics BIOC First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Discovery
BIOC Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. Informational Platform Analytics Process execution Discovery
Analytics IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics BIOC IAM instance profile associations were described AWS IAM instance profile associations were described. Informational Cortex Cloud AWS Audit Log Discovery
Analytics BIOC IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. Informational Cortex Cloud AWS Audit Log Discovery
BIOC Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. Informational Platform Analytics Process execution Discovery
BIOC Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. Informational Platform Analytics Process execution Discovery
Analytics BIOC Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. Informational Platform Analytics XDR Agent Privilege Escalation, Discovery
Analytics BIOC Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. Informational Platform Analytics XDR Agent Discovery
Analytics BIOC Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. Informational Platform Analytics XDR Agent Discovery
BIOC Linux network share discovery A Linux network share discovery command was executed. Informational Platform Analytics Process execution Discovery
Analytics BIOC Local account discovery One of several local account discovery commands were executed. Informational Platform Analytics XDR Agent Discovery
Analytics Local group enumeration A user performed an enumeration on local groups to retrieve their details. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Local group enumeration via RPC A user enumerated local groups via RPC. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Local user enumeration via SAMR A user enumerated local users via SAMR. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Log enumeration via cloud native logging service An activity of log enumeration operations via cloud native logging service was detected. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Mailbox enumeration activity by Azure application Microsoft Graph API was used to enumerate mailboxes in Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneDrive enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneDrive items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneNote enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneNote items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft SharePoint enumeration activity The Microsoft Graph API was used to enumerate Microsoft SharePoint sites in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft Teams enumeration activity The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
BIOC Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. Informational Platform Analytics Process execution Discovery
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
BIOC Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. Informational Platform Analytics Process execution Discovery
BIOC Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. Informational Platform Analytics Process execution Discovery
Analytics BIOC Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access, Discovery
BIOC Password complexity enumeration Attackers may read system files containing password complexity requirements. Informational Platform Analytics Process execution Discovery
BIOC Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. Informational Platform Analytics Process execution Discovery
Analytics BIOC Permission Groups discovery commands Permission group discovery command execution. Informational Platform Analytics XDR Agent Discovery
BIOC Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. Informational Platform Analytics Process execution Discovery
Analytics Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls Discovery
Analytics Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
BIOC Possible ARP reconnaissance The ARP binary could be used for network mapping (common with malware). Informational Platform Analytics Process execution Discovery
BIOC Possible ARP reconnaissance via netdiscover Netdiscover is an active/passive ARP reconnaissance tool, which attackers may use to learn your network. Informational Platform Analytics Process execution Discovery
Analytics BIOC Possible GPO Enumeration A possible GPO enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration of Microsoft Configuration Manager A possible enumeration on Microsoft Configuration Manager via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible LDAP Enumeration Tool Usage A user sent a suspicious enumeration query via LDAP. The query is associated with an LDAP enumeration tool that may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible SPN enumeration A possible SPN enumeration via LDAP was performed. Such enumeration may be used during attacks against the organization. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics BIOC Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
BIOC Possible user enumeration via /etc/passwd Attackers may enumerate users by reading the /etc/passwd file. Informational Platform Analytics Process execution Discovery
BIOC Possible user enumeration via finger The Linux 'finger' command performs user enumeration, which attackers may attempt to gather during the reconnaissance phase. Informational Platform Analytics Process execution Discovery
BIOC Potential Network Sniffing Network sniffing related processes were detected. Informational Platform Analytics Process execution Credential Access, Discovery
BIOC Query startup programs using wmic.exe Attackers may use wmic.exe to query programs that run automatically when users log onto the computer system. Informational Platform Analytics Process execution Discovery, Execution
BIOC Reading the contents of /etc/mtab or /etc/fstab File read on /etc/mtab or /etc/fstab using the cat utility. Informational Platform Analytics Process execution Discovery
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
BIOC Remote system discovery Remote system discovery using a system utility. Informational Platform Analytics Process execution Discovery
Analytics SCCM log files enumeration Multiple local SCCM logs were accessed within a short period of time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery