Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

71 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud instance was stopped A cloud compute instance was stopped. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC A container registry was created or deleted A container registry was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Google Workspace Role privilege was deleted A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A Google Workspace user was removed from a group A user removed another user from a Google Workspace group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics BIOC A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes Pod was deleted A Kubernetes Pod was deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes service was created or deleted A Kubernetes service was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A service was disabled A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. Informational Platform Analytics XDR Agent Impact
Analytics BIOC A third-party application's access to the Google Workspace domain's resources was revoked An identity removed a third-party application's access to Google Workspace domain's resources. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Impact
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics BIOC An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An AWS SES identity was deleted An AWS SES identity has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure virtual network Device was modified An Azure virtual network Device was modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC An Azure virtual network was modified An Azure virtual network has been modified or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC Aurora DB cluster stopped An Aurora DB cluster (RDS) was stopped. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup recovery point deletion An attempt was made to delete an AWS Backup recovery point. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS Backup vault was deleted An AWS Backup vault was deleted by a cloud identity. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS EBS snapshot deletion An attempt was made to delete an EBS snapshot. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Broker Collection Error A collection error was detected on a broker VM. Informational Platform Analytics Health Monitoring Data Impact
Analytics BIOC Cloud identity reached a throttling API rate A cloud identity has executed a high volume of API calls, causing a throttling error. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage automatic backup disabled Automatic backup of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC Cloud storage delete protection disabled Delete protection of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
BIOC Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. Informational Platform Analytics Process execution Defense Evasion, Impact
Analytics BIOC Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Impact
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Subscription Deletion A GCP Pub/Sub subscription was deleted. An attacker might use this technique to affect business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Pub/Sub Topic Deletion A GCP Pub/Sub topic was deleted, might affect workflows due to interrupts within the Pub/Sub pipeline. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Cloud (VPC) Network Deletion A GCP VPC network was deleted. An attacker might use this technique to interrupt business resources and workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Creation A GCP VPC route was created. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Virtual Private Network Route Deletion A GCP VPC route was deleted. An attacker might use this technique to impact business workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC Kubernetes network policy modification A change has been made to the network policies of a Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
BIOC Manipulation of permissions for the Application Event Log Removing read/write permissions from this key may result in errors in the Application event log, and may cause certain VSS diagnostic tools to not function correctly. https://technet.microsoft.com/en-us/library/cc734219(v=ws.10).aspx. Informational Platform Analytics Registry Impact
BIOC Manipulation of Volume Shadow Copy configuration Modifying this key might remove VSS privileges from user accounts, possibly disabling Volume Shadow Copy. Informational Platform Analytics Registry Impact
Analytics Massive files deletion in Box A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Box Audit Log Impact
Analytics Massive files deletion in Dropbox A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) DropBox Impact
Analytics Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Google Workspace Audit Logs Impact
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
BIOC Modification of Windows boot configuration using bcdedit.exe BCDEdit is a Microsoft Windows utility that can modify boot parameters. It is usually used as part of an attack to prevent repair of the affected system by disabling booting in recovery mode. It can also be used to stop Windows' Patchguard from objecting to the unsigned and insecure nature of a driver being loaded. Informational Platform Analytics Process execution Defense Evasion, Impact
Analytics Multiple user accounts were deleted A user deleted multiple user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Impact
Analytics BIOC Object versioning was disabled Object versioning of a cloud storage resource was disabled. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Impact
Analytics BIOC PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. Informational Cortex Cloud Azure Audit Log Impact
BIOC Possible data destruction via dd Attackers may use dd to zero out or write random data to files. Informational Platform Analytics Process execution Impact
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Impact
BIOC Shutdown command issued This behavior is often observed by malware attempting to force a machine shutdown after a period of time once file encryption has completed. Informational Platform Analytics Process execution Impact
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact
Analytics BIOC System shutdown or reboot System shutdown or reboot using shutdown, reboot, halt or poweroff. Informational Platform Analytics XDR Agent Impact
Analytics BIOC Uncommon service stop operation An attempt to stop a service was made using an unusual shell command. Informational Platform Analytics XDR Agent Impact
Analytics Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact
BIOC WMI access to shadow copy interface An attacker may be trying to modify and/or delete shadow copies via WMI for disabling system backups or extracting NTDS.dit. Informational Platform Analytics Process execution Credential Access, Impact