Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

14 detectors match the current filters. tactic: TA0003 ✕ technique: T1098 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. Low Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC SPNs cleared from a machine account Service principal names were cleared from a machine account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious modification of the AdminSDHolder's ACL A user modified the AdminSDHolder ACL, which may be an indication of a privilege escalation attack. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Suspicious sAMAccountName change The name of a machine account was changed to a sAMAccountName with a missing trailing dollar sign. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. Low Platform Analytics XDR Agent Persistence
Analytics User added to the SMS Admins local group A user was added to the SMS Admins local group. This may indicate a potential attack targeting the Microsoft Configuration Manager infrastructure. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation