Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. tactic: TA0009 ✕ technique: T1119 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A user performed suspiciously massive file activity A user generated massive file activity by size or distinct file count. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| BIOC | Forensics Driver Loaded A forensics driver has been loaded. | Informational | Platform Analytics | Module | Collection, Credential Access |
| Analytics | Massive file activity abnormal to process A user generated massive file activity by size or distinct file count. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics BIOC | Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Collection, Initial Access |
| Analytics BIOC | Retrieval of cloud compute EC2 instance user data A cloud compute instance user data was retrieved, which may contain startup scripts, configuration parameters, or sensitive information associated with the instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| BIOC | WinPmem Forensics Tool The WinPmem Forensics Tool has been run. | Informational | Platform Analytics | Process execution | Collection, Credential Access |