Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. tactic: TA0005 ✕ technique: T1556 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | An app was added to the Google Workspace trusted OAuth apps list An identity added an OAuth app to the Google Workspace trusted OAuth apps list. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | An app was removed from a blocked list in Google Workspace An identity removed an app from Google Workspace blocked OAuth or third-party apps list. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | An AWS SAML provider was modified An AWS SAML provider was modified. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Defense Evasion |
| Analytics BIOC | MFA was disabled for a Google Workspace user Multi-Factor Authentication (MFA) has been disabled for a Google Workspace user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | MFA was disabled for an Azure identity MFA was disabled for the user. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access, Defense Evasion, Persistence |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics BIOC | Suspicious authentication with Azure Password Hash Sync user Authentication to an unusual authentication target was performed by the Azure AD Password Hash Sync user. | Medium | Identity Analytics | AzureAD | Initial Access, Defense Evasion |
| Analytics BIOC | Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. | Informational | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Defense Evasion, Persistence |