Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
21 detectors match the current filters. tactic: TA0001 ✕ technique: T1078 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. | Low | Cortex Cloud | Gcp Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. | Low | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access, Execution |
| Analytics BIOC | A disabled user attempted to log in to a VPN A disabled user attempted to log in suspiciously to a VPN. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Collection |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics BIOC | Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access |
| Analytics BIOC | FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | Interactive login by a service account A service account performed an interactive or remote interactive login. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics | Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | New FTP Server A new FTP server has been detected. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Initial Access, Collection |
| Analytics | New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. | Low | Identity Analytics | XDR Agent | Initial Access |
| Analytics BIOC | Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | AzureAD, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a machine account A machine account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | SSO authentication by a service account A service account successfully authenticated via SSO. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access |
| Analytics BIOC | Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | VPN login attempt by a honey user A VPN login attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |
| Analytics BIOC | VPN login by a service account A service account attempted to log in to a VPN service. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Initial Access |