Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
17 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Execution |
| Analytics | A contained process attempted to escape using the 'notify on release' feature A contained process attempted to escape the host by leveraging the Docker's 'notify on release' feature. The calling process modified relevant files that might trigger a command on the host. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | A new machine attempted Kerberos delegation A newly created machine attempted to perform a Kerberos delegation. This suspicious activity might indicate a Kerberos relay attack. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics | An unsigned process created scheduled task and performed an injection An unsigned process created scheduled task and performed an injection. | Medium | Platform Analytics | XDR Agent | Persistence, Defense Evasion |
| Analytics | Azure Privilege Escalation Using an Application An Azure application was observed assigning an Azure administrator role to a user. This might indicate a privilege escalation attempt. | Medium | Identity Threat Detection (ITDR) | AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation |
| Analytics | Cloud IMDS access followed by remote token usage A request was made to the cloud Instance Metadata Service (IMDS) followed by a remote usage of EC2 role token. | Medium | Cortex Cloud | AWS Audit Log, XDR Agent | Initial Access, Credential Access |
| Analytics | Command execution via AWS SSM A cloud identity performed multiple unusual activities leading to code execution using AWS Systems Manager service. | Medium | Cortex Cloud | AWS Audit Log | Execution, Lateral Movement |
| Analytics | Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. | Medium | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics | New Administrative Behavior The endpoint performed new administrative actions, relative to its previously profiled behavior. It is possible that an endpoint will infrequently be used for administrative activities, so analytics is performed using logs collected over a long period of time, also comparing the activity to that of other endpoints. That is, if many endpoints are contacting the same destination with the same administrative activity, then this network activity is less likely to result in this alert. An attacker may be operating on the host, probing other computers and moving laterally inside the network using a trusted computer and credentials. Attackers typically exhibit administrative behaviors when performing reconnaissance and lateral movement. | Medium | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Lateral Movement |
| Analytics | NTLM Hash Harvesting An unusual number of users has sent NTLM to a target in the last hour. This may be indicative of poisoning and NTLM hash harvesting. | Medium | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Possible AS-REP Roasting Attack A user enumerated all accounts that don't require pre-authentication in the organization and specifically requested tickets for those accounts. This is typically a sign of an AS-REP Roasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Possible Kerberoasting attack A user enumerated all service principals in the organization and specifically requested weak and deprecated encryption in a ticket request. This is typically a sign of a Kerberoasting attack. | Medium | Identity Analytics | XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | Potential Phishing has been detected This email contains multiple indicators consistent with a phishing attack. The message likely attempts to steal credentials, distribute malware, or trick recipients into performing actions that compromise security through deceptive content or suspicious technical characteristics. | Medium | Email Security | Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log | Initial Access |
| Analytics | Random-Looking Domain Names The endpoint performed DNS lookups to an excessively large number of apparently random root domain names. This alert might be symptomatic of malware that is trying to connect to its command and control (C2) servers. The attacker's C2 server runs on one or more domains that can eventually be identified and blacklisted. To avoid this, malware will sometimes use Domain Generation Algorithms (DGA) that produce many unique, random-looking domain names every day. Because only a few of these domains are ever registered, the installed malware must blindly try to access each generated domain name in an effort to locate an active one, which may also trigger the Failed DNS alert. | Medium | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Command and Control |
| Analytics | Sudoedit Brute force attempt An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156. | Medium | Platform Analytics | XDR Agent | Privilege Escalation |
| Analytics | Suspicious Azure enumeration activity An Azure identity performed resource enumeration across multiple services using Microsoft Graph. | Medium | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |