Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

29 detectors match the current filters. technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. Low Cortex Cloud Gcp Audit Log Initial Access, Credential Access
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A disabled user attempted to log in to a VPN A disabled user attempted to log in suspiciously to a VPN. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. Low Identity Analytics XDR Agent Initial Access, Credential Access
Analytics BIOC Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC Azure AD PIM role settings change An identity changed the PIM role settings. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access
Analytics BIOC FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics New Shared User Account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics Short-lived user account A user was created and deleted within a short period of time. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion
Analytics BIOC SPNs cleared from a machine account Service principal names were cleared from a machine account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC SSO authentication attempt by a honey user An SSO authentication attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a machine account A machine account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC SSO authentication by a service account A service account successfully authenticated via SSO. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious sAMAccountName change The name of a machine account was changed to a sAMAccountName with a missing trailing dollar sign. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence
Analytics BIOC Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. Low Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics User added to the SMS Admins local group A user was added to the SMS Admins local group. This may indicate a potential attack targeting the Microsoft Configuration Manager infrastructure. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC VPN login attempt by a honey user A VPN login attempt was made by a honey user, a decoy account created specifically to detect unauthorized access. This may indicate potential attacker activity. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC VPN login by a service account A service account attempted to log in to a VPN service. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access