Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

24 detectors match the current filters. tactic: TA0040 ✕ technique: T1485 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A container registry was created or deleted A container registry was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes cluster was created or deleted A Kubernetes cluster was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC A Kubernetes Pod was deleted A Kubernetes Pod was deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Impact
Analytics BIOC An AWS EFS File-share mount was deleted An AWS EFS File-share mount was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EFS file-share was deleted An AWS EFS File-share has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An AWS RDS Global Cluster Deletion An AWS RDS global cluster was deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An AWS SES identity was deleted An AWS SES identity has been deleted. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC An Azure Kubernetes Cluster was created or deleted An Azure Kubernetes Cluster was created or deleted. Informational Cortex Cloud Azure Audit Log Impact
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS RDS cluster deletion A previously provisioned DB cluster (RDS) was deleted. When a DB cluster is being deleted, all automated backups for that DB cluster are deleted and can't be recovered. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Broker Collection Error A collection error was detected on a broker VM. Informational Platform Analytics Health Monitoring Data Impact
BIOC Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. Informational Platform Analytics Process execution Defense Evasion, Impact
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket deletion A GCP bucket was deleted. An attacker might use this technique to destroy business data and its workflows. Informational Cortex Cloud Gcp Audit Log Impact
Analytics Massive files deletion in Box A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Box Audit Log Impact
Analytics Massive files deletion in Dropbox A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) DropBox Impact
Analytics Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Google Workspace Audit Logs Impact
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
BIOC Possible data destruction via dd Attackers may use dd to zero out or write random data to files. Informational Platform Analytics Process execution Impact
Analytics Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Unusual resource modification by newly seen IAM user A cloud resource was modified by a newly seen IAM user. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence, Privilege Escalation, Impact