Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

4 detectors match the current filters. tactic: TA0009 ✕ technique: T1530 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. Low Cortex Cloud Azure Audit Log, Gcp Audit Log Exfiltration, Collection
Analytics Microsoft 365 storage services exfiltration activity The Microsoft Graph API was used to download Microsoft OneDrive and SharePoint files. Low Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics Suspicious access to Kubernetes API with kubelet credentials A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster. Low Cortex Cloud XDR Agent with eXtended Threat Hunting (XTH) Exfiltration, Collection
Analytics Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration