Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
139 detectors match the current filters. tactic: TA0006 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. | Low | Cortex Cloud | Gcp Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. | Low | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access, Execution |
| Analytics BIOC | A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Credential Access |
| Analytics BIOC | A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | A process queried the ADFS database decryption key via LDAP A process queried the ADFS database decryption key (DKM key) via LDAP. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | A user attempted to bypass Okta MFA A user may have attempted to bypass Okta MFA. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Credential Access |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user connected from a new country A user connected from an unusual country that the user has not connected from before. This may indicate the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics BIOC | A user connected to a VPN from a new country A user connected to a VPN from an unusual country that the user has not connected from before. This may indicate the account was compromised. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access, Resource Development |
| Analytics BIOC | A user created a pfx file for the first time A user created a pfx file for the first time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | A user logged in from an abnormal country or ASN A user logged in from an unusual country or ASN. This may indicate that the account was compromised. | Informational | Identity Analytics | XDR Agent | Credential Access, Resource Development |
| Analytics BIOC | A user modified an Okta MFA factor An Okta MFA factor was modified by a user, suggesting a potential compromise of the account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Credential Access, Persistence |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Access to kubelet credentials file A process accessed a kubelet credentials file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | ADFS DKM Key Access ADFS DKM key attribute (thumbnailphoto) access in AD container, potential Golden SAML token forging attempt. | Low | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | An Azure Key Vault key was modified An Azure Key Vault key was modified. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An Azure Key Vault was modified Azure Key Vault has been modified or deleted by an Identity. This could be an indication of unauthorized access or malicious activity. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | An identity accessed Azure Kubernetes Secrets An identity has accessed or attempted to access Azure Kubernetes secrets or Config Objects. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS SSM parameters retrieval An attempt was made to retrieve parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access |
| Analytics BIOC | AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Initial Access, Credential Access |
| Analytics BIOC | Azure application consent An identity consented permissions to an application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Copy a process memory file Copy a process memory file using the dd utility. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Email contains URL delivering high-risk file type Emails with URLs linking to file types commonly blocked by email vendors due to their use in malware delivery. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | External email with a single internal recipient hidden in BCC External email with mailbox owner hidden in BCC as the only internal recipient. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | First connection from a country in organization A user connected to an SSO service from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics BIOC | First VPN access attempt from a country in organization A user attempted to connect from an unusual country that no one from this organization has connected from before. This may indicate the account was compromised. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access, Resource Development |
| Analytics BIOC | First-time attachment exchange Detects when an attachment is sent between individuals for the first time in 30 days. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics BIOC | Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access, Persistence |
| Analytics BIOC | Granting Access to an Account Azure access has been granted to an account. | Informational | Cortex Cloud | Azure Audit Log | Initial Access, Credential Access |
| Analytics BIOC | Hydra Password Brute-Force Tool Execution Attackers may use brute-force techniques to gain access to accounts when usernames and/or passwords are unknown. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Initial person-to-person email contact Identifies when a sender initiates contact with individuals with no prior history of interaction in the last 30 days. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Invalid SAML Detected A user attempted to sign in using an invalid SAML. This might indicate a Golden SAML attack. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD, Okta | Credential Access |
| Analytics BIOC | Key credential attribute modification A user modified the msDS-KeyCredentialLink attribute for an account, which may indicate a shadow credentials attack. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Keylogging using system commands Usage of a Linux system utility to capture input. | Low | Platform Analytics | XDR Agent | Credential Access, Collection |
| Analytics BIOC | Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Credential Access |
| Analytics BIOC | Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Credential Access |
| Analytics BIOC | LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | LSASS dump file written to disk Dumping Lsass.exe (Local Security Authority Subsystem Service) memory to file allows attackers to later extract credentials from the memory dump. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Memory dumping with comsvcs.dll A process memory dump was performed using comsvcs.dll MiniDump. This method is commonly used by attackers to dump Lsass.exe (Local Security Authority Subsystem Service) process memory to a file, so they could later extract credentials from the memory dump. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | MFA Disabled for Google Workspace An administrator has disabled Multi-Factor Authentication for Google Workspace users. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access |
| Analytics BIOC | MFA was disabled for an Azure identity MFA was disabled for the user. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access, Defense Evasion, Persistence |
| Analytics BIOC | Mimikatz command-line arguments These command-line arguments are often used by Mimikatz to dump and harvest credentials. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Modification of NTLM restrictions in the Registry Allowing the transmission of NTLM could be part of an NTLM downgrade or an Internal Monologue attack. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Modification of PAM Modification of PAM configuration files. | Informational | Platform Analytics | XDR Agent | Persistence, Defense Evasion, Credential Access |
| Analytics BIOC | Moniker link detected in URL(s) A Moniker link was detected within the email's body. The link has the convention of a Moniker link (CVE-2024-21413) correlated to a suspicious URL scheme. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Multiple uncommon SSH Servers with the same Server host key Multiple uncommon SSH servers were observed using the same host key. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics BIOC | Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Discovery |
| Analytics BIOC | NTDS.dit file written by an uncommon executable The Active Directory database file was written by an uncommon process to a non-default location. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Outbound email contains file-sharing service link sent to external recipient Identifies outbound emails that include links to file-sharing services sent externally. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Outbound email includes an external BCC recipient observed for the first time Internal sender BCC'd an external recipient whose address has not been observed in prior communications. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Outbound email to an address hosted by a public email service provider Internal sender emailed to an address hosted by a public email service provider. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics BIOC | Owner added to Azure application An identity was added as an owner to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Credential Access |
| Analytics BIOC | Possible authentication coercion An unusual Remote Procedure Call (RPC) was made to potentially cause authentication coercion. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible DCSync from a non domain controller Attackers may pose a compromised host as a DC to replicate data to it (DCSync). | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Defense Evasion |
| Analytics BIOC | Possible Distributed File System Namespace Management (DFSNM) abuse A possible abuse of Distributed File System Namespace Management (DFSNM). | High | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Possible Kerberoasting without SPNs A user specifically requested weak and deprecated encryption in a Kerberos TGS request. This provides easy-to-crack hashes, and is typically a sign of a Kerberoasting attack. The requested service was specified by using a suspicious SPN type, which is often used by Kerberoasting tools to request by SAN instead of SPN. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics BIOC | Possible network sniffing attempt via tcpdump or tshark Attackers may monitor network traffic for cleartext credentials or to learn the network's configuration. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics BIOC | Possible new DHCP server A DHCP response was sent from an unknown DHCP server. Attackers may send a DHCP response to a host in his LAN to inject a DNS server, route or WPAD server. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible Search For Password Files Attackers often search for files that have passwords in them. | Medium | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Possible use of a networking driver for network sniffing A process wrote a known networking driver with network sniffing capabilities to disk, attackers can use it to sniff passwords and other credentials from the network. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access, Discovery |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Potential DCSync by an unusual user Attackers may leverage the domain replication process to extract sensitive information (DCSync). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Defense Evasion, Credential Access |
| Analytics BIOC | Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Execution, Credential Access |
| Analytics BIOC | PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Procdump executed from an atypical directory Procdump.exe is a SysInternals tool used to dump process memory; it can be used to dump lsass.exe memory to extract credentials. | Medium | Platform Analytics | XDR Agent | Defense Evasion, Credential Access |
| Analytics BIOC | Rare process accessed a Keychain file An unusual process accessed a Keychain file. This might indicate a credential-grabbing attempt. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. | Low | Cortex Cloud | AWS Audit Log | Credential Access, Lateral Movement, Initial Access |
| Analytics BIOC | Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. | Low | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Remote usage of an Azure Service Principal token An Azure Service Principal token was used externally of the cloud environment. | Informational | Cortex Cloud | Azure Audit Log | Credential Access |
| Analytics BIOC | Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Initial Access |
| Analytics BIOC | Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. | Informational | Cortex Cloud | Gcp Audit Log | Credential Access |
| Analytics BIOC | Retrieval of kubelet credentials A process retrieved kubelet credentials. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Sensitive browser credential files accessed by a rare non browser process Sensitive browser credential files accessed by a rare non browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Stored credentials exported using credwiz.exe Attackers may abuse the credwiz tool to export stored accounts. | Low | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious access to shadow file An unpopular process accessed the shadow file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious certificate template modification A certificate template was updated with a possible misconfiguration. This may indicate the exploitation of misconfigured certificate template access control (ESC4). | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious Certutil AD CS contact A suspicious occurrence of Certutil attempted to contact the AD CS Request Interface. | Low | Platform Analytics | XDR Agent | Discovery, Credential Access |
| Analytics BIOC | Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin Attackers may attempt to dump the ntds.dit file, which stores all Active Directory account information, to later extract passwords and hashes from it. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics BIOC | Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious NTLM authentication with machine account A suspicious NTLM authentication attempt was made by a machine account. | Informational | Identity Analytics | Palo Alto Networks Firewall EAL Logs, XDR Agent | Credential Access |
| Analytics BIOC | Suspicious Print System Remote Protocol usage by a process A host which is trusted for unconstrained delegation initiated an SMB connection to a DC using the Print System Remote Protocol. An attacker can abuse such sessions for relay attacks. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious process accessed certificate files A suspicious process accessed certificate files. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |