Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

9 detectors match the current filters. tactic: TA0005 ✕ technique: T1556 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Defense Evasion, Persistence
Analytics BIOC An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC An AWS SAML provider was modified An AWS SAML provider was modified. Informational Cortex Cloud AWS Audit Log Initial Access, Defense Evasion
Analytics BIOC MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Defense Evasion
Analytics BIOC MFA was disabled for an Azure identity MFA was disabled for the user. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access, Defense Evasion, Persistence
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
Analytics BIOC Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. Medium Identity Analytics AzureAD Initial Access, Defense Evasion
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence