Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0006 ✕ technique: T1556 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access
Analytics BIOC A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Credential Access, Persistence
Analytics BIOC Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access, Persistence
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics BIOC Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC MFA Disabled for Google Workspace An administrator has disabled Multi-Factor Authentication for Google Workspace users. Low Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Credential Access
Analytics BIOC MFA was disabled for an Azure identity MFA was disabled for the user. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Credential Access, Defense Evasion, Persistence
Analytics BIOC Modification of PAM Modification of PAM configuration files. Informational Platform Analytics XDR Agent Persistence, Defense Evasion, Credential Access
BIOC Pluggable Authentication Modules Access Access to Pluggable Authentication Modules. Informational Platform Analytics Process execution Credential Access
BIOC Pluggable Authentication Modules Modification Modification of Pluggable Authentication Modules. Informational Platform Analytics File Credential Access
Analytics BIOC Weakly-Encrypted Kerberos TGT Response A weakly encrypted Kerberos TGT was issued by a domain controller. The encryption type is abnormal for this DC and results in a TGT that is easier to crack. This behavior may indicate a Skeleton Key attack. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Credential Access, Defense Evasion, Persistence