Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
15 detectors match the current filters. technique: T1098 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. | Low | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics | New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Privileged role used by Azure application An Azure application with high-level API permissions invoked a request to the Microsoft Graph API. | Low | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Privilege Escalation |
| Analytics BIOC | SPNs cleared from a machine account Service principal names were cleared from a machine account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious modification of the AdminSDHolder's ACL A user modified the AdminSDHolder ACL, which may be an indication of a privilege escalation attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious sAMAccountName change The name of a machine account was changed to a sAMAccountName with a missing trailing dollar sign. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics | User added to the SMS Admins local group A user was added to the SMS Admins local group. This may indicate a potential attack targeting the Microsoft Configuration Manager infrastructure. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |