Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
177 detectors match the current filters. tactic: TA0007 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics BIOC | A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment A new server has been added to an Azure Active Directory Hybrid Health AD FS Environment. | Informational | Cortex Cloud | Azure Audit Log | Discovery |
| Analytics BIOC | A suspicious process queried AD CS objects via LDAP A suspicious process queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. | Informational | Identity Threat Detection (ITDR) | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Discovery, Initial Access |
| Analytics BIOC | A user changed the Windows system time A user changed the Windows system time. This may be indicative of a malicious activity and may affect authentication from the source machine. | Informational | Identity Threat Detection (ITDR) | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | A user queried AD CS objects via LDAP A user queried AD CS objects via LDAP. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics | Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics | Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. | Low | Platform Analytics | XDR Agent | Discovery |
| BIOC | Active directory enumeration using built-in nltest.exe Nltest.exe is a command-line tool used for network administrative tasks, and can be used to gather information about domain controllers and users. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | ADFind queries Active Directory for Exchange groups A process executed with ADFind parameters and used to extract data on built-in groups for the Exchange server (e.g. "Organization Management"). | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Administrator groups enumerated via LDAP An LDAP search query that collects information about administrators was executed. This may be indicative of Active Directory domain enumeration, which can be used to perform attacks against the organization. | Informational | Platform Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | An Azure application reached a throttling API rate An Azure application has executed a high volume of Microsoft Graph API calls, causing a throttling error. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. | Medium | Cortex Cloud | XDR Agent | Discovery, Impact |
| Analytics | AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Password Policy Discovery A cloud identity has viewed the AWS account password policy. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS principals discovery A cloud identity has enumerated principals. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS resource discovery A cloud identity has enumerated resources. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Secrets Manager discovery An attempt was made to list secrets from AWS Secrets Manager. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics | AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS SSM association created with inventory collection document An identity created an AWS Systems Manager State Manager association using the AWS-GatherSoftwareInventory document. This document collects software inventory from managed instances and can be used by attackers for host discovery and enumeration. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Execution |
| Analytics BIOC | AWS SSM parameters discovery An attempt was made to list parameters stored in AWS SSM. | Informational | Cortex Cloud | AWS Audit Log | Credential Access, Discovery |
| Analytics BIOC | AWS Storage Gateway enumeration An AWS Storage Gateway was enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS Storage Gateway file share enumeration AWS Storage Gateway file shares were enumerated. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | AWS Systems Manager hosts enumeration A cloud identity enumerated hosts managed by AWS Systems Manager. Adversaries may use this API to discover SSM managed instances as a precursor to lateral movement or remote code execution. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics BIOC | Browser bookmark files accessed by a rare non-browser process Browser bookmark files accessed by a rare non-browser process. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Cached credentials discovery with cmdkey Cmdkey is a built-in Windows tool that can cache domain user credentials for use on specific target machines, Attackers can access cached user credentials using cmdkey /list. | Low | Platform Analytics | XDR Agent | Credential Access, Discovery |
| Analytics | Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log | Discovery |
| Analytics | Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics | Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery |
| BIOC | Container enumeration An attacker may run a command to enumerate containers on a machine. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Discovery of accounts with pre-authentication disabled via LDAP A possible discovery of accounts without pre-authentication required via LDAP was performed. Such enumeration may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | Discovery of host users via WMIC Attackers may use wmic.exe to list the users of a host, and potentially its owner. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Discovery of misconfigured certificate templates using LDAP An LDAP query searching for misconfigured certificate templates was executed. | Medium | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| BIOC | DNS reconnaissance or enumeration via DNSRecon DNSRecon enables DNS reconnaissance and enumeration, and may be used by attackers to learn about targets' network infrastructure. | Medium | Platform Analytics | Process execution | Discovery |
| BIOC | Document discovery Attackers may use the find command to look for documents. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration command called by commonly abused CGO Some malware uses these commands for reconnaissance. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of installed AV or FW products using WMIC Attackers often check for the existence of security tools before launching an attack, and this is one of the methods that can be used. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Enumeration of services via WMIC Attackers may enumerate existing services using wmic.exe. | Informational | Platform Analytics | Process execution | Discovery, Execution |
| BIOC | Enumeration of Windows services from public IP addresses Attackers may enumerate internet-facing services which use Windows protocols; as these services were not meant to be exposed to the internet, they may be attacked by enumerating users, brute-forcing passwords and through exploits. | Informational | Platform Analytics | Dml connection | Discovery |
| BIOC | Evasion using time-based properties Attackers may check Event Log to evade virtualized environments. | Informational | Platform Analytics | Process execution | Defense Evasion, Discovery |
| BIOC | Execution of Fsociety tool pack The Fsociety tool pack is an array of tools for information gathering, password attacks, exploitation, and more. | Medium | Platform Analytics | Process execution | Discovery, Credential Access |
| Analytics | Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Discovery |
| Analytics BIOC | First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Initial Access, Discovery |
| BIOC | Group policy discovery using gpresult.exe Attackers may use gpresult.exe to gather information on Group Policy settings. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Discovery |
| Analytics BIOC | IAM instance profile associations were described AWS IAM instance profile associations were described. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics BIOC | IAM role-attached managed policies were listed AWS IAM managed policies that are attached to a role were listed. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| BIOC | Installation of networking security tools A security or penetration testing tool such as wireshark and nmap is being installed. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. | Low | Identity Analytics | XDR Agent | Discovery, Credential Access |
| BIOC | Interface enumeration using netsh Attackers may enumerate existing network interfaces using netsh.exe. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Kerberos Traffic from Non-Standard Process The endpoint had a non-standard process communicating over ports normally used by Kerberos. An attacker might be using malicious tools to move laterally. | Medium | Platform Analytics | XDR Agent | Discovery |
| Analytics | Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. | Medium | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Discovery |
| Analytics BIOC | Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. | Informational | Platform Analytics | XDR Agent | Privilege Escalation, Discovery |
| Analytics BIOC | Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics | Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. | Medium | Platform Analytics | XDR Agent | Execution, Discovery |
| Analytics BIOC | Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution, Discovery |
| Analytics BIOC | LDAP AD CS Enumeration via Attack Tool A user sent a suspicious AD CS enumeration query via LDAP. The query is associated with an AD CS LDAP enumeration tool that may be used during attacks against the organization. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery, Credential Access |
| Analytics BIOC | LDAP search query from an unpopular and unsigned process An unpopular and unsigned process performed an LDAP search query. This may be indicative of LDAP enumeration. | Low | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | LDAP traffic from non-standard process LDAP traffic is usually performed by a standard set of processes. The endpoint had a non-standard process communicating over ports normally used by LDAP. This may be indicative of Active Directory domain enumeration, which may be used during attacks against the organization. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Linux network share discovery An adversary might use known tools to discover SMB shares within the compromised network. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Linux network share discovery A Linux network share discovery command was executed. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Local account discovery One of several local account discovery commands were executed. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Local group enumeration A user performed an enumeration on local groups to retrieve their details. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Local group enumeration via RPC A user enumerated local groups via RPC. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics BIOC | Local user enumeration via SAMR A user enumerated local users via SAMR. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |
| Analytics | Log enumeration via cloud native logging service An activity of log enumeration operations via cloud native logging service was detected. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | Mailbox enumeration activity by Azure application Microsoft Graph API was used to enumerate mailboxes in Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | Microsoft OneDrive enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneDrive items. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | Microsoft OneNote enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneNote items. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | Microsoft SharePoint enumeration activity The Microsoft Graph API was used to enumerate Microsoft SharePoint sites in an Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| Analytics | Microsoft Teams enumeration activity The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Discovery |
| BIOC | Mounted NFS share discovery Attackers may use the showmount command to list mount Network File Sharing shares. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics | Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Discovery, Defense Evasion |
| Analytics | Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. | Low | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| BIOC | Network Packet Capture: tshark/tcpdump Network packet capture using tshark\tcpdump utility. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network scanning tool executed This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Network share discovery via command-line tool Attackers may use command-line tools to discover mapped shares on the host. | Low | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Network sniffing detected in Cloud environment A network sniffing tool was used in a cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Credential Access, Discovery |
| BIOC | Password complexity enumeration Attackers may read system files containing password complexity requirements. | Informational | Platform Analytics | Process execution | Discovery |
| BIOC | Password policy discovery via command-line tool Attackers may use chage to list the password policy and the user's last access time. | Informational | Platform Analytics | Process execution | Discovery |
| Analytics BIOC | Permission Groups discovery commands Permission group discovery command execution. | Informational | Platform Analytics | XDR Agent | Discovery |
| BIOC | Permission groups discovery via ldapsearch Attackers may use the ldapsearch command-line tool to gather information about domain groups and their permissions. | Informational | Platform Analytics | Process execution | Discovery |