Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

200 detectors match the current filters. tactic: TA0003 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A browser extension was installed or loaded in an uncommon way A browser extension was installed or loaded in an uncommon way. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics BIOC A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A contained executable was executed by an unusual process A Docker-contained executable from a mounted share was executed on a host. Running a contained executable is highly dangerous and atypical. Medium Platform Analytics XDR Agent Privilege Escalation, Persistence
Analytics BIOC A Google Workspace identity created, assigned or modified a role A Google Workspace identity created, assigned or modified a delegated admin role. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace identity performed an unusual admin console activity A Google Workspace identity performed an admin console activity for the first time. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace user was added to a group A user added another user to a Google Workspace group. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Kubernetes cluster role was created A Kubernetes cluster role was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Privilege Escalation
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes Cronjob was created A Kubernetes CronJob was created. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Microsoft Teams application was installed A Microsoft Teams application was installed. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC A Microsoft Teams bot was added to a team A user added a bot to a team in Microsoft Teams. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Persistence
Analytics BIOC A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process A signed DLL was loaded into a Microsoft-signed process. This DLL hash and signature vendor are rare, which might indicate an attacker performing DLL hijacking. Informational Platform Analytics XDR Agent Persistence, Privilege Escalation, Defense Evasion
Analytics BIOC A rare file path was added to the AppInit_DLLs registry value A rare file path was added to AppInit_DLLs registry value. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics BIOC A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access, Persistence
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC A user was added to a Windows security group A user was added to a Windows security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A WMI subscriber was created A WMI subscriber was created. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS Lambda Function was created An AWS Lambda Function was created. Informational Cortex Cloud AWS Audit Log Execution, Persistence
Analytics BIOC An Email address was added to AWS SES An Email address was added to AWS SES. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An IAM group was created An IAM group was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An uncommon file added to startup-related Registry keys An attacker may add a file to the Registry "Run Keys" or the "Winlogon\Userinit" key to cause it to be executed as the user logs in. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon file was created in the startup folder An uncommon file was created in the startup folder. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC An uncommon lolbin execution by scheduled task A lolbin was executed with uncommon commandline by a scheduled task. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC An uncommon service was started An uncommon service was started using systemctl or service processes. Low Platform Analytics XDR Agent Persistence, Privilege Escalation
Analytics BIOC An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC Authentication method added to an Azure account An identity attempted to add an Azure authentication method. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Authentication method was added to Azure account A new authentication method was added to an Azure AD user. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Autorun.inf created in root C drive An autorun file installed at the root of a C:\ drive is suspicious, as autorun files are typically associated with removable drives. Medium Platform Analytics XDR Agent Persistence, Lateral Movement
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. Low Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC AWS user creation A new AWS user was created. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure application credentials added An identity added credentials to an Azure application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure application URI modification An identity added or updated an Azure application's URI. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Persistence
Analytics BIOC Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure device code authentication flow used An Azure AD login was performed with device code flow. Informational Identity Analytics Azure Audit Log Defense Evasion, Persistence
Analytics BIOC Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence, Privilege Escalation
Analytics BIOC Azure Event Hub Authorization rule creation/modification An authorization rule is bound with specific rights, once created within a namespace, which has management permissions. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure group creation/deletion A group in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure permission delegation granted An identity delegated permissions to access a certain resource or application. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Service principal/Application creation An Azure Service principal/Application was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure user creation/deletion A user in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure user password reset The password of an Azure AD user was reset. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. Informational Cortex Cloud Azure Audit Log Execution, Persistence, Defense Evasion
Analytics BIOC Bitsadmin.exe persistence using command-line callback BITSAdmin.exe was used with a command-line that may indicate malware trying to gain persistence on the machine. Medium Platform Analytics XDR Agent Persistence
Analytics BIOC Browser Extension Installed Uncommon browser extension installed. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Chrome Extension Installed By User A Chrome extension was installed or updated by a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Persistence
Analytics BIOC Cloud access key creation Cloud access key creation by a cloud identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Persistence
Analytics BIOC Credentials were added to Azure application Credentials were added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Persistence
Analytics BIOC Executable or Script file written by a web server process An uncommon executable or script file was created, written, or renamed by a web server process. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics BIOC Execution of an uncommon process at an early startup stage Uncommon execution of an executable found in an early startup stage. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process at an early startup stage by Windows system binary Uncommon execution of an executable found in an early startup stage by Windows system binary. Low Platform Analytics XDR Agent Persistence
Analytics BIOC Execution of an uncommon process with a local/domain user SID at an early startup stage Execution of an uncommon process with a local/domain user SID at an early startup stage may be an indication of a persistent mechanism on boot that is being actively abused. Informational Platform Analytics XDR Agent Persistence
Analytics BIOC External user invitation to Azure tenant An external user was invited to Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence, Privilege Escalation
Analytics BIOC First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. Low Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. Informational Cortex Cloud Gcp Audit Log Persistence
Analytics BIOC GCP set IAM policy activity A cloud identity had modified a resource policy bindings. Informational Cortex Cloud Gcp Audit Log Persistence, Privilege Escalation
Analytics BIOC Globally uncommon injection from a signed process A signed process injected into another process that it does not normally target at a global level. Informational Platform Analytics XDR Agent Defense Evasion, Persistence
Analytics BIOC Google Workspace automation was created Google Workspace automation was created. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Execution, Persistence, Exfiltration
Analytics BIOC Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was created An AWS IAM instance profile was created. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy version was created A cloud identity created an AWS-managed IAM policy version. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. Informational Cortex Cloud AWS Audit Log Persistence, Privilege Escalation
Analytics BIOC IAM policy was attached to role An AWS IAM policy was attached to this role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence