Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
17 detectors match the current filters. technique: T1070 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | AWS SecurityHub findings were modified AWS SecurityHub findings were modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure mailbox rule creation A Mailbox rule in Azure was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection, Defense Evasion |
| BIOC | Clearing logs by copying /dev/null to a log file Usage of the cp command to copy /dev/null to a file and clear its content. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Clearing logs by executing cat /dev/null Usage of cat /dev/null to clear the contents of a log file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Data destruction using sdelete.exe Attackers may use sdelete.exe to delete files from the target host. | Informational | Platform Analytics | Process execution | Defense Evasion, Impact |
| Analytics BIOC | Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Impact |
| Analytics BIOC | Deletion of AD CS certificate database entries A user has deleted rows from the certificate database of an AD CS server. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | File timestamp tampering An attacker may modify file timestamps by running the touch command to hide their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Log deletion in known log file directories Deletion of log files in known log directories. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | Log deletion using the truncate command Usage of the truncate utility using "-s 0" argument to clear log files. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Log deletion via command-line tool An attacker may use the rm command to remove traces of their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Possible log destruction using the dd command Possible destruction of system log files using the dd command. | Informational | Platform Analytics | File | Defense Evasion |
| BIOC | PowerShell is used to modify a timestamp Attackers may use PowerShell.exe to modify the timestamp of a file. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Removal of an Azure Owner from an Application or Service Principal An Azure Owner was removed from an application or service principal. This may indicate malicious activity or unauthorized access to the application or service. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics | User moved Exchange sent messages to deleted items A user moved sent messages to deleted items in Exchange. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Windows event logs were cleared with PowerShell Windows event logs were cleared or deleted with PowerShell. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Windows Security audit log was cleared Event ID 1102 was generated when the Windows Security audit log was cleared. Attackers may clear events from Windows event logs to remove traces of their malicious activity. | Informational | Platform Analytics | Windows event log | Defense Evasion |