Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

81 detectors match the current filters. technique: T1562 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. Informational Identity Threat Detection (ITDR) XDR Agent Defense Evasion
Analytics BIOC A cloud identity created or modified a security group A cloud identity created or modified a security group. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC A user modified an Okta network zone An Okta network zone was modified by a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Defense Evasion
Analytics BIOC An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure Suppression Rule was created An Azure Suppression Rule was created. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC An identity disabled bucket logging An identity disabled bucket logging. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudTrail modification An identity updated a CloudTrail trail configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. Informational Cortex Cloud AWS Audit Log Impact, Defense Evasion
Analytics BIOC AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS network ACL rule deletion An AWS network ACL rule was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. Informational Cortex Cloud Azure Audit Log Defense Evasion, Impact
Analytics BIOC Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. Informational Cortex Cloud Azure Audit Log Defense Evasion, Execution
Analytics BIOC Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. Informational Cortex Cloud Azure Audit Log Impact, Defense Evasion
Analytics BIOC Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
BIOC Chrome launched in Incognito mode May be used to cover up malware or malicious insider activity. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Lateral Movement
BIOC Clear event logging policy using auditpol.exe Attackers may clear Windows Event Logging policies using auditpol.exe. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Cloud resource logging was disabled Cloud resource logging was disabled. Informational Cortex Cloud Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC Cloud Watch alarm deletion A Cloud Watch alarm was deleted. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC CloudTrail logging deletion CloudTrail logging trail deletion. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Data encryption was disabled A cloud identity has disabled data encryption. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion, Impact
Analytics BIOC Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
BIOC Disable outlook security via Registry Attackers may try to disable outlook security features by modifying the Registry. Informational Platform Analytics Registry Defense Evasion
BIOC Disabling Windows Defender via Registry Windows Defender stores its configuration in the Registry. By modifying these values, an attacker can disable security features. Informational Platform Analytics Registry Defense Evasion
BIOC Fltmc.exe used to unload filter driver Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC Indicator blocking Auditing or logging configuration changes on Linux host. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Internet Explorer security settings modification The Security Settings Check feature, which checks Internet Explorer security settings to determine risk, was disabled. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC Iptables configuration command was executed The iptables process was executed with a command to add or delete rules on the host. Informational Platform Analytics XDR Agent Defense Evasion
Analytics BIOC Kubernetes cluster events deletion Kubernetes cluster events deletion. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Defense Evasion
BIOC MacOS firewall manipulation An attacker may modify a firewall via command line to bypass network controls. Informational Platform Analytics Process execution Defense Evasion
BIOC Manipulation of Windows Defender configuration Commands used to bypass, disable or harm Windows Defender. Informational Platform Analytics Process execution Defense Evasion
BIOC Manipulation of Windows Event Log auto-backup via Registry This key enables/disables the automatic backups of event logs when they are full. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. Informational Cortex Cloud AWS Audit Log Defense Evasion
Analytics BIOC Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Defense Evasion
Analytics BIOC Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Persistence
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
BIOC Netsh.exe modifies allowed firewall port/program lists Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
BIOC Security services stopped Attackers may stop security critical services to avoid possible detection of their activities. Informational Platform Analytics Process execution Defense Evasion
BIOC SELinux was set to permissive mode SELinux was set to permissive mode using the "setenforce 0" command. Informational Platform Analytics Process execution Defense Evasion
BIOC SmartScreen disabled via Registry These Registry keys control the SmartScreen. Malware may turn it off to evade SmartScreen functionality. Informational Platform Analytics Registry Defense Evasion
Analytics BIOC Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. Informational Cortex Cloud AWS Audit Log Defense Evasion
BIOC Suspicious usage of cytool.exe The Cortex XDR agent can be controlled by a command-line tool named cytool.exe. Attackers may use it to disable the Cortex XDR agent. Informational Platform Analytics Process execution Defense Evasion
Analytics BIOC Tampering with Internet Explorer Protected Mode configuration When an add-on is running inside Protected Mode attempts to launch a broker process (or any other program), the ElevationPolicy Registry key is checked to determine how the process should be launched. Internet Explorer will run a broker process with higher rights that can use the current user's permissions to take actions that would otherwise be prohibited when rendering content inside the Protected Mode sandbox. https://blogs.msdn.microsoft.com/ieinternals/2009/11/30/understanding-the-protected-mode-elevation-dialog/. Informational Platform Analytics XDR Agent Defense Evasion
BIOC Tampering with Windows certificate blocking configuration Adding subkeys of the certificates to block disallows a security vendor's certificate on the affected computer, so that Windows would not allow the program to run. Informational Platform Analytics Registry Defense Evasion
BIOC Tampering with Windows Control Panel configuration DLLs with .cpl suffix are executed when accessing the Control Panel. Malicious code may run this way even if AppLocker enabled. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall disabled via Registry An attacker may disable the Windows Firewall via the Registry to bypass network controls. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Firewall notifications disabled via Registry These Registry keys control the Windows Firewall notifications. Malware may turn notifications off before editing the firewall settings. Informational Platform Analytics Registry Defense Evasion
BIOC Windows PowerShell Logging being disabled via Registry Tampering of the key can disable event logging by the PowerShell, allowing the adversary to evade being detected using PowerShell. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Registry Editor being disabled via Registry Registry Editor may be enabled / disabled using this key. This could indicate either IT policy applied or malicious activity preventing the user from altering the Registry. Informational Platform Analytics Registry Defense Evasion
BIOC Windows Task Manager being disabled via Registry Task manager may be disabled to tamper with the user experience and with the response to a malicious incident. Informational Platform Analytics Registry Defense Evasion
BIOC WMI terminated a process The Windows Management Instrumentation CLI killed another process running on the endpoint or on a remote host. Malware may do this to evade detection. Informational Platform Analytics Process execution Defense Evasion, Execution