Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
2 detectors match the current filters. tactic: TA0007 ✕ technique: T1654 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | Log enumeration via cloud native logging service An activity of log enumeration operations via cloud native logging service was detected. | Informational | Cortex Cloud | AWS Audit Log | Discovery |
| Analytics | SCCM log files enumeration Multiple local SCCM logs were accessed within a short period of time. | Informational | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Discovery |