Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
114 detectors match the current filters. tactic: TA0005 ✕ technique: T1562 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A browser was opened in private mode A browser was opened in private mode, which may indicate an attempt to cover tracks. | Informational | Identity Threat Detection (ITDR) | XDR Agent | Defense Evasion |
| Analytics BIOC | A cloud identity created or modified a security group A cloud identity created or modified a security group. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | A domain was added to the trusted domains list A domain was added to the Google Workspace trusted domains list. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| Analytics BIOC | A user added a Windows firewall rule A user added a new Windows Firewall rule. Adding a firewall rule may indicate an attempt to bypass controls limiting network usage or to disrupt network communications. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | A user modified an Okta network zone An Okta network zone was modified by a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion |
| Analytics BIOC | A user modified an Okta policy rule An Okta policy rule was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | A user modified the CA audit policy A user modified the CA audit policy. This may indicate that an attacker is attempting to cover their tracks before an AD CS attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | AI safeguards deletion attempt A cloud identity deleted AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| Analytics BIOC | AI safeguards were modified A cloud identity modified AI safeguards. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Defense Evasion |
| BIOC | AMSI Bypass AMSI (Antimalware Scan Interface) provides enhanced malware protection on Windows 10 machines. Attackers may try to bypass this mechanism and run malicious code. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | An AWS GuardDuty IP set was created An AWS GuardDuty IP set has been created. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Impact |
| Analytics BIOC | An Azure Firewall policy deletion An Azure Firewall policy was deleted. An attacker might use this technique to disable network defenses. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall rule collection group was modified or deleted An Azure Firewall rule collection group was modified or deleted. This could indicate a malicious actor attempting to bypass security measures. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure firewall rule group was modified An Azure firewall rule group was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Firewall was modified An Azure Firewall was modified or deleted. This may indicate a security risk. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Network Security Group was modified An Azure Network Security Group was modified or deleted. This could indicate malicious activity or a misconfiguration. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Point-to-Site VPN was modified An Azure Point-to-Site VPN was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure Suppression Rule was created An Azure Suppression Rule was created. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An Azure VPN Connection was modified Modification or removal of an Azure VPN connection was detected. This alert indicates a change to an existing VPN connection or the deletion of an existing connection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | An identity disabled bucket logging An identity disabled bucket logging. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Bedrock model invocation logging deletion A cloud identity deleted the model invocation logging. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail has been stopped A cloud trail logging has been stopped, which indicates that AWS API calls are not recorded in that trail. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudTrail modification An identity updated a CloudTrail trail configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS CloudWatch log group deletion An AWS CloudWatch log group was deleted, this action permanently deletes all the archives associated with this group. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS CloudWatch log stream deletion An AWS CloudWatch log stream was deleted, this action permanently deletes all the archives associated with this stream. | Informational | Cortex Cloud | AWS Audit Log | Impact, Defense Evasion |
| Analytics BIOC | AWS Config Recorder stopped Configuration Recorder was stopped for a resource in AWS Config. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS config resource deletion An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Flow Logs deletion A cloud identity has deleted one or more Flow Logs records. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Guard-Duty detector deletion AWS Guard-Duty detector was deleted. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS network ACL rule deletion An AWS network ACL rule was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket data retention policy change through S3 Lifecycle rule A retention policy was set on a S3 bucket used by a CloudTrail Trail, using a S3 Lifecycle Rule. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS Security Group remote access allowed from an unknown external IP address A cloud identity has modified the ingress rules to allow unfamiliar ip addresses SSH or RDP access. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS web ACL deletion Web ACL defines a collection of rules to use to inspect and control web requests. A Web ACL has been deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure Automation Runbook Deletion An Azure Automation runbook was deleted. This could disrupt business automation processes or remove a malicious runbook that was part of an attack. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Impact |
| Analytics BIOC | Azure diagnostic configuration deletion An attacker might delete the Azure diagnostic settings to evade detection. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Event Hub Deletion An Azure event hub was deleted. An attacker might use this technique to evade detection. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Kubernetes events were deleted Events have been deleted in Azure Kubernetes. This could indicate malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Monitor alert rule deleted An Azure Monitor alert rule was deleted. Azure Monitor alert rules watch telemetry from cloud resources and fire when suspicious or anomalous activity occurs. Adversaries may delete these rules to blind defenders and avoid detection of follow-on malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Execution |
| Analytics BIOC | Azure Network Watcher Deletion Azure Network Watchers are used for monitoring and diagnosing Azure resources. An attacker might use this technique to avoid security mitigations. | Low | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure Resource Group Deletion Resource group deletion permanently deletes all resources within the group, An attacker might use this technique to avoid detection or destroy procedures/data. | Informational | Cortex Cloud | Azure Audit Log | Impact, Defense Evasion |
| Analytics BIOC | Azure storage account was publicly shared Azure Storage Account network permissions modified to public, exposing data to any network and unauthorized identities. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion |
| Analytics BIOC | Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. | Informational | Cortex Cloud | Azure Audit Log | Execution, Persistence, Defense Evasion |
| BIOC | Chrome launched in Incognito mode May be used to cover up malware or malicious insider activity. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Chrome OS Remote Access policy was modified in Google Workspace A user modified Chrome OS Remote Access configuration in Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Lateral Movement |
| BIOC | Clear event logging policy using auditpol.exe Attackers may clear Windows Event Logging policies using auditpol.exe. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Cloud AI agent was modified A cloud identity modified AI agent. MITRE ATLAS Technique: AML.T0015 - Evade ML Model. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Organizational policy was created or modified Cloud organizational policy was created or modified. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud resource logging was disabled Cloud resource logging was disabled. | Informational | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Cloud Watch alarm deletion A Cloud Watch alarm was deleted. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | CloudTrail logging deletion CloudTrail logging trail deletion. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Data encryption was disabled A cloud identity has disabled data encryption. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Data Sharing between GCP and Google Workspace was disabled An identity has modified data sharing settings between GCP and Google Workspace. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion, Impact |
| Analytics BIOC | Disable AWS audit logs through Event Selectors An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Disable Microsoft Defender Antivirus via registry Disable Microsoft Defender Antivirus via registry. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| BIOC | Disable outlook security via Registry Attackers may try to disable outlook security features by modifying the Registry. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | Disabling Windows Defender via Registry Windows Defender stores its configuration in the Registry. By modifying these values, an attacker can disable security features. | Informational | Platform Analytics | Registry | Defense Evasion |
| BIOC | EventLog service disabled by a Registry operation A Registry set-value operation that disables the EventLog service was executed on the machine. | High | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | Exchange anti-phish policy disabled or removed A user disabled or removed an Exchange anti-phish policy, which may indicate evasion of a possible phishing campaign. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange audit log disabled A user disabled the Exchange audit log. This may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange DKIM signing configuration disabled A user disabled an Exchange DomainKeys Identified Mail (DKIM) signing configuration. DKIM helps ensure that emails are authorized and not spoofed. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange mailbox audit bypass A user added mailbox audit bypass for an account. This will allow the account to perform actions without being logged, and may indicate an attempt to evade detection. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange malware filter policy removed A user removed an Exchange malware filter policy, which may prevent the detection of malware. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Exchange Safe Attachment policy disabled or removed A user disabled an Exchange Safe Attachment policy, which provides phishing protection to email attachments. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| Analytics BIOC | Exchange Safe Link policy disabled or removed A user disabled an Exchange Safe Link policy, which provides phishing protection to emails that contain hyperlinks. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion, Initial Access |
| BIOC | Fltmc.exe used to unload filter driver Attackers can abuse the Filter Manager Control Program (fltMC.exe) to unload MiniFilter drivers, some of which may be used for activity monitoring. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | GCP data asset shared public The GCP data asset was publicly shared. | Low | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule creation A GCP VPN firewall rule was created. An attacker might use this technique to block or open access to/from restricted areas. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Firewall Rule Modification A GCP firewall rule was modified. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP Logging Bucket Deletion A GCP logging bucket was deleted. An attacker might delete the bucket to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink deletion A GCP logging sink entity was deleted. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP logging sink modification A GCP logging sink entity was modified. Logs that match the logging sink rule will not arrive at their destination. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | GCP VPC Firewall Rule Deletion A GCP VPC firewall rule was deleted. An attacker might use this technique to access restricted resources. | Informational | Cortex Cloud | Gcp Audit Log | Defense Evasion |
| Analytics BIOC | Indicator blocking Auditing or logging configuration changes on Linux host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Internet Explorer security settings modification The Security Settings Check feature, which checks Internet Explorer security settings to determine risk, was disabled. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | Iptables configuration command was executed The iptables process was executed with a command to add or delete rules on the host. | Informational | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Kubernetes cluster events deletion Kubernetes cluster events deletion. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Defense Evasion |
| Analytics BIOC | Linux system firewall was modified The system firewall was modified. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Logging was impaired via external encryption key The resource was configured with an external key This might be an attempt to disrupt log inspection. | Medium | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Impact, Defense Evasion |
| BIOC | MacOS firewall manipulation An attacker may modify a firewall via command line to bypass network controls. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Manipulation of Windows Defender configuration Commands used to bypass, disable or harm Windows Defender. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | Manipulation of Windows Event Log auto-backup via Registry This key enables/disables the automatic backups of event logs when they are full. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | MFA device was removed/deactivated from an IAM user Deactivate an MFA device and disassociate it from an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Microsoft 365 DLP policy disabled or removed A user disabled or removed a Microsoft 365 data loss prevention (DLP) policy, which may indicate DLP monitoring evasion. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Defense Evasion |
| Analytics BIOC | Microsoft Teams application setup policy was modified Microsoft Teams the application setup policy, which is responsible for application management, was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Persistence |
| Analytics BIOC | Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Defense Evasion, Exfiltration |
| BIOC | Netsh.exe modifies allowed firewall port/program lists Malware will often modify local firewall settings to permit untrusted software to communicate with the Internet for C2. Check for malicious use. | Informational | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | New addition to Windows Defender exclusion list Windows Defender keeps the exclusion list in the registry, and any addition to it will cause it to ignore a process, path or file extension. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| BIOC | Process attempts to kill a known security/AV tool This process has attempted to use taskkill.exe to terminate a known AV process or security analysis tool. Likely attempt to evade detection. | Medium | Platform Analytics | Process execution | Defense Evasion |
| Analytics BIOC | Security object deletion in Google Workspace Admin Console A security object was deleted in Google Workspace Admin Console. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Defense Evasion |
| BIOC | Security services stopped Attackers may stop security critical services to avoid possible detection of their activities. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | SELinux was set to permissive mode SELinux was set to permissive mode using the "setenforce 0" command. | Informational | Platform Analytics | Process execution | Defense Evasion |
| BIOC | SmartScreen disabled via Registry These Registry keys control the SmartScreen. Malware may turn it off to evade SmartScreen functionality. | Informational | Platform Analytics | Registry | Defense Evasion |
| Analytics BIOC | Suspicious activity on logging bucket An identity performed a suspicious activity on bucket used to store logs. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion |
| BIOC | Suspicious AMSI DLL load location An attacker may attempt to load a malicious copy of amsi.dll to bypass Microsoft's Antimalware Scan Interface (AMSI). | Low | Platform Analytics | Module | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall The Windows Firewall has been disabled. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Low | Platform Analytics | XDR Agent | Defense Evasion |
| Analytics BIOC | Suspicious disablement of the Windows Firewall using PowerShell commands The Windows Firewall has been disabled using PowerShell. Malware may turn it off to exfiltrate data and communicate with C2 servers. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion |
| Analytics BIOC | Suspicious SSH Downgrade The endpoint asked for an ssh downgrade, ssh downgrade may enable attackers to perform attacks such as data decryption, man in the middle, session hijack, replay attack and more. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Lateral Movement, Defense Evasion |