Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
24 detectors match the current filters. tactic: TA0040 ✕ technique: T1485 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A container registry was created or deleted A container registry was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | A Kubernetes Pod was deleted A Kubernetes Pod was deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Impact |
| Analytics BIOC | An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Impact |
| Analytics BIOC | An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An AWS SES identity was deleted An AWS SES identity has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Broker Collection Error A collection error was detected on a broker VM. | Informational | Platform Analytics | Health Monitoring Data | Impact |
| BIOC | Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| Analytics | Deletion of multiple cloud resources An identity deleted multiple cloud resources. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics | Massive files deletion in Box A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | Box Audit Log | Impact |
| Analytics | Massive files deletion in Dropbox A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | DropBox | Impact |
| Analytics | Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | Google Workspace Audit Logs | Impact |
| Analytics | Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. | Informational | Identity Threat Detection (ITDR) | Office 365 Audit | Impact |
| BIOC | Possible data destruction via dd Attackers may use dd to zero out or write random data to files. | Informational | Platform Analytics | Process execution | Impact |
| Analytics | Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Privilege Escalation, Impact |