Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
6 detectors match the current filters. tactic: TA0006 ✕ technique: T1606 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. | Low | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics BIOC | Granting Access to an Account Azure access has been granted to an account. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Invalid SAML Detected A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD, Okta | Credential Access |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Unusual ADFS Remote Synchronization network connections from non-ADFS server Detected an unauthorized configuration sync request to the ADFS Policy Store from a non-ADFS server, step for forging SAML tokens in a Golden SAML attack. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access, Lateral Movement |