Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. technique: T1114 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics BIOC | Azure mailbox rule creation A Mailbox rule in Azure was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection, Defense Evasion |
| Analytics BIOC | Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |
| Analytics BIOC | Gmail routing settings changed Gmail routing settings were modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics BIOC | Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. | Informational | Platform Analytics | XDR Agent | Collection |
| Analytics BIOC | SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. | Informational | Email Security | Office 365 Audit | Collection |
| BIOC | Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. | Informational | Platform Analytics | File | Collection |
| Analytics | Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection, Exfiltration |