Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
66 detectors match the current filters. tactic: TA0010 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Cloud DB instance was exported to an unknown destination A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | A GCP Cloud SQL DB instance was exported from a production account A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | A process connected to a rare cloud resource A process connected to a rare cloud resource. | Informational | Platform Analytics | XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration, Initial Access |
| Analytics BIOC | A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. | Informational | Identity Threat Detection (ITDR) | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration |
| Analytics BIOC | A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics | A user printed an unusual number of files A user printed an unusual number of files. This may be indicative of malicious activity and an attempt to exfiltrate data. | Informational | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Exfiltration |
| Analytics BIOC | Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics BIOC | An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An Azure SQL database was exported from a production subscription An Azure SQL database export was initiated. The database was exported from a production subscription. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated for export from a production subscription A SAS URL for an Azure VM snapshot was generated. The operation was performed within a production subscription. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration, Defense Evasion |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Exfiltration |
| Analytics BIOC | AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| BIOC | BitTorrent P2P file sharing The host used BitTorrent for P2P file sharing (according to the App-ID), which is typically not allowed in corporate networks and may be used to exfiltrate information. | Informational | Platform Analytics | Dml connection | Exfiltration |
| Analytics BIOC | Bucket's block public access setting turned off S3 bucket block public access setting turned off. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| BIOC | Curl connects to an external network Curl is a command-line utility used to transfer data. Attackers may use curl to exfiltrate data outside your organization. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics BIOC | EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | External Sharing was turned on for Google Drive An identity has modified Google Drive sharing settings and allowed external sharing. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Exfiltration |
| Analytics BIOC | First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| Analytics BIOC | Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | Google Workspace automation was created Google Workspace automation was created. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Execution, Persistence, Exfiltration |
| Analytics | Massive upload to a rare storage or mail domain A large amount of data was transferred to an external site that is used for mail or storage. This behavior may indicate data exfiltration. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, XDR Agent | Exfiltration |
| Analytics | Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit | Exfiltration, Collection |
| BIOC | Microsoft Office spawns curl/wget on a macOS device Microsoft Office Word/Excel/PowerPoint/Outlook spawn wget/curl on a macOS device. | Informational | Platform Analytics | Process execution | Exfiltration |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| Analytics | Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration |
| Analytics | Possible data exfiltration over a USB storage device A process generated massive file creation, renaming and write activity to a USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics | Possible internal data exfiltration over a USB storage device A user generated abnormal massive file activity to a connected USB storage device. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Collection, Exfiltration |
| Analytics BIOC | Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Possible use of IPFS was detected The host produced traffic consistent with IPFS. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Exfiltration, Initial Access |
| Analytics BIOC | Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| Analytics BIOC | Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Exfiltration |
| Analytics BIOC | Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| BIOC | Scripting engine makes connections over DNS ports Scripting engine makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics | Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics | Suspicious DNS traffic 10 KB or more were sent encoded in subdomain names during a 10-minute window. All subdomains queried were under a single suspicious domain. DNS tunneling encodes data in DNS queries and responses, allowing an attacker to bypass firewalls and proxies to reach his or her command and control server, even when HTTP/S traffic is blocked. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Command and Control, Exfiltration |
| Analytics | Uncommon increase in Azure Microsoft Graph API request sizes An identity executed multiple Microsoft Graph actions, leading to an uncommon increase in API request sizes. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Exfiltration |
| Analytics BIOC | Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. | Informational | Platform Analytics | XDR Agent | Command and Control, Exfiltration |
| BIOC | Unsigned process makes connections over DNS ports An unsigned process makes connections over DNS ports should not happen, as DNS traffic is typically managed by svchost and sometimes the browsers. Attackers are known to use DNS traffic to exfiltrate data and avoid detection. | Informational | Platform Analytics | Network | Exfiltration |
| Analytics | Unusual attachment volume in outbound emails Numerous emails with substantial attachments sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Exfiltration |
| Analytics BIOC | User signed in to an application via Power Automate for the first time A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Exfiltration |
| Analytics BIOC | WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. | Informational | Platform Analytics | XDR Agent | Exfiltration |
| BIOC | Wget connection to an external network Wget is a command-line utility used to transfer data. Attackers may use wget to exfiltrate data outside your organization. | Informational | Platform Analytics | Network | Exfiltration |