Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
65 detectors match the current filters. tactic: TA0009 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| BIOC | 7z.exe execution with password protection parameters 7z.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics | A user accessed an abnormal number of remote shared folders A user accessed an abnormal number of remote shared folders. This might indicate an attempt to collect data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | A user created an abnormal password-protected archive A user created an abnormal password-protected archive using an archive program. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | A user performed suspiciously massive file activity A user generated massive file activity by size or distinct file count. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | A user took numerous screenshots A user took numerous screenshots. A valuable organization's information may have been collected in this way. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Azure mailbox rule creation A Mailbox rule in Azure was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection, Defense Evasion |
| BIOC | Built-in SoundRecorder tool capturing audio SoundRecorder is a built-in voice recording tool. Besides benign usage, it may be used to discreetly record a user. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | Cloud compute volume creation attempt An attempt was made to create an EBS volume. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Collection |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| BIOC | Command-line creation of a RAR archive Compression of data into a RAR archive using the rar.exe utility. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Compressed archive created using tar Attackers may use the tar built-in tool to stage a file for exfiltration. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| BIOC | Encrypted zip archive creation Attackers may stage information for exfiltration by encrypting it beforehand in a zip archive. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics | External SaaS file-sharing activity A user shared files from within a SaaS service to an external domain. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| Analytics BIOC | Gmail routing settings changed Gmail routing settings were modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics | Large volume of files potentially containing credentials accessed in Google Drive A user accessed a large volume of files potentially containing credentials in Google Drive. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection, Credential Access |
| Analytics | Massive file activity abnormal to process A user generated massive file activity by size or distinct file count. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | Massive file compression by user Multiple archive files were created by a user. This might indicate an attempt to stage data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | Massive file downloads from SaaS service A user downloaded a large volume of files from an organizational SaaS service, either exceeding the normal file count or size for the user's typical behavior. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Exfiltration, Collection |
| Analytics BIOC | Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | OneDrive file download A file was downloaded from OneDrive using the Microsoft Graph API. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection |
| Analytics BIOC | OneDrive folder creation A folder was created in OneDrive using Microsoft Graph API. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection |
| Analytics | Possible data exfiltration over a USB storage device A process generated massive file creation, renaming and write activity to a USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. | Informational | Platform Analytics | XDR Agent | Collection |
| Analytics | Possible internal data exfiltration over a USB storage device A user generated abnormal massive file activity to a connected USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Collection, Initial Access |
| BIOC | PowerShell script executed from a temporary directory An attacker may try to avoid detection by executing a PowerShell script from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Rar.exe execution with password protection parameters Rar.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |
| Analytics BIOC | Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Retrieval of cloud compute EC2 instance user data A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| Analytics BIOC | SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. | Informational | Email Security | Office 365 Audit | Collection |
| BIOC | Screen capture via command-line tool Attackers may use the window system screen capture tool to collect screenshots. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Scripting engine creates a compressed file under a suspicious folder Attackers may compress data before exfiltrating it to reduce network bandwidth consumption; if a compressed file is placed in a suspicious folder, it may be due to malicious activity. | Informational | Platform Analytics | File | Collection |
| BIOC | Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. | Informational | Platform Analytics | File | Collection |
| Analytics | Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | File | Credential Access, Collection |
| BIOC | Shell History Access Access to files holding shell history information. | Informational | Platform Analytics | Process execution | Credential Access, Collection |
| Analytics | Suspicious AWS SSM parameters retrieval activity An identity dumped multiple AWS SSM parameters from the project. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Collection |
| Analytics BIOC | Suspicious ML Model Download A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection |
| Analytics | Suspicious secrets dump activity An identity dumped multiple secrets from the project, considerably more than usual. This may indicate an attacker's attempt to dump sensitive information from the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Collection |
| Analytics BIOC | Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line The AppleScript interpreter was executed with a script designed to access cryptocurrency wallet data. | Informational | Platform Analytics | XDR Agent | Execution, Collection |
| Analytics BIOC | Uncommon GetClipboardData API function invocation of a possible information stealer An unpopular process accessed clipboard content by calling the GetClipboardData API function. This behavior may indicate potential threats such as a keylogger or a RAT. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Collection |
| Analytics | User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| BIOC | Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. | Informational | Platform Analytics | File | Collection |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |
| BIOC | Wscript / Cscript executed from a temporary directory An attacker may try to avoid detection by executing wscript/cscript scripts from a temporary directory. | Informational | Platform Analytics | Process execution | Collection |
| BIOC | Wzzip.exe execution with password protection parameters Wzzip.exe was executed with parameters indicating password protection of the output file. | Informational | Platform Analytics | Process execution | Collection |