Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

51 detectors match the current filters. tactic: TA0007 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user accessed an abnormal number of files on a remote shared folder A user remotely accessed an abnormal number of files on a remote shared folder. This might indicate an attempt to collect data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics A user accessed multiple unusual resources via SSO A user accessed multiple resources via SSO that are unusual for this user. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Discovery, Initial Access
Analytics A user executed multiple LDAP enumeration queries A user executed multiple LDAP enumeration queries. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Abnormal connections to a dormant host from a newly seen endpoint The endpoint has performed multiple connections to an endpoint that is relatively inactive on the network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Abnormal ICMP echo (PING) to multiple hosts An endpoint performed an abnormal ICMP echo (PING) to multiple hosts on the network. Low Platform Analytics XDR Agent Discovery
Analytics AI model discovery A cloud identity listed available AI models. This behavior often suggests reconnaissance on AI models and potential misuse. MITRE ATLAS Technique: AML.T0007 - Discover ML Artifacts. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics An Azure identity performed multiple actions that were denied An identity performed multiple Microsoft Graph actions that were denied, which may indicate it is being misused. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics AWS Bedrock AI infrastructure enumeration activity Bedrock AI infrastructure enumeration activity detected, potentially indicating reconnaissance on AI resources. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS EBS enumeration activity EBS volume and snapshot enumeration activity, potentially indicating block storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS EC2 infrastructure enumeration activity EC2 infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS Lambda infrastructure enumeration activity Lambda infrastructure enumeration activity detected within a specific AWS region. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS S3 Buckets enumeration activity Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics AWS Security Service Enumeration AWS security service enumeration activity, potentially indicating reconnaissance. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Azure enumeration activity using Microsoft Graph API The Microsoft Graph API was used to enumerate an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Cloud email infrastructure enumeration activity A cloud identity attempted to discover available email sending resources within the cloud environment. This may indicate an adversary attempting to map the organization's email sending environment and discover cloud resources that may assist to send phishing emails or spam. Informational Cortex Cloud AWS Audit Log, Azure Audit Log Discovery
Analytics Cloud infrastructure discovery across multiple regions Discovery API calls were executed across multiple AWS regions. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Cloud infrastructure enumeration activity A cloud identity attempted to discover available resources within the cloud environment. This may indicate an adversary attempting to map the organization's cloud environment and discover cloud resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics Cloud user performed multiple actions that were denied An identity performed multiple actions that were denied, which may indicate it is being misused. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics Failed Connections The endpoint has failed connections to other endpoints that have been inactive for more than 24 hours, or that Cortex XDR Analytics has never seen on the network. The endpoint has made an abnormally large number of these failed connections and/or is attempting to connect to an abnormal mixture of missing or inactive endpoints. Your network might contain legitimate scanners that could cause a false positive for this alert. Cortex XDR Analytics attempts to filter these out by checking if a scanner has been active for a long consecutive period of time. Consequently, if this alert is seen, it represents new activity on your network. An attacker may be trying to move laterally, or to scan different parts of the network to look for other endpoints that expose a specific service. Worms also perform a similar activity to automatically infect additional hosts in the network. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics IAM Enumeration sequence An identity has executed a sequence of events which may be related to an IAM recon enumeration. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Discovery
Analytics Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. Low Identity Analytics XDR Agent Discovery, Credential Access
Analytics Kerberos User Enumeration A high amount of Kerberos principal unknown errors were generated on users in the last hour. This may be indicative of Kerberos user enumeration. Medium Identity Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Discovery
Analytics Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Discovery
Analytics Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. Informational Platform Analytics XDR Agent Discovery
Analytics Local group enumeration A user performed an enumeration on local groups to retrieve their details. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Log enumeration via cloud native logging service An activity of log enumeration operations via cloud native logging service was detected. Informational Cortex Cloud AWS Audit Log Discovery
Analytics Mailbox enumeration activity by Azure application Microsoft Graph API was used to enumerate mailboxes in Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneDrive enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneDrive items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft OneNote enumeration activity The Microsoft Graph API was used to enumerate Microsoft OneNote items. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft SharePoint enumeration activity The Microsoft Graph API was used to enumerate Microsoft SharePoint sites in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Microsoft Teams enumeration activity The Microsoft Graph API was used to enumerate Microsoft Teams channels in an Azure tenant. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Multi region enumeration activity An internal identity performed an operation on multiple regions, considerably more than usual. This may indicate an attacker's attempt to identify all available resources in the cloud environment. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery, Defense Evasion
Analytics Multiple discovery commands The alerted causality performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Linux host by the same process The alerted process performed multiple consecutive discovery commands in a short timeframe. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple discovery commands on a Windows host by the same process The alerted process performed multiple discovery commands in a short timeframe. Low Platform Analytics XDR Agent Discovery
Analytics Multiple discovery-like commands The alerted process performed multiple consecutive discovery commands in a short time frame. Informational Platform Analytics XDR Agent Discovery
Analytics Multiple failed AWS assume role attempts An AWS identity performed an unusual high number of failed assume role attempts. Informational Cortex Cloud AWS Audit Log Discovery, Privilege Escalation
Analytics Port Scan The endpoint connected, or attempted to connect, to multiple privileged ports, which are infrequently used by other endpoints (i.e. destination ports that are normally used by many endpoints will not raise this alert). Attackers perform port scans for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port scans using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, Third-Party Firewalls Discovery
Analytics Port Sweep The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Discovery
Analytics Possible Kerberos User Enumeration Multiple Kerberos TGT requests with KDC_ERR_C_PRINCIPAL_UNKNOWN errors were generated on different users in the last 10 minutes which may indicate Kerberos user enumeration. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Possible LDAP enumeration by unsigned process An unsigned process performed multiple different LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Rare LDAP enumeration Possible LDAP enumeration with a rare combination of queries. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Discovery
Analytics Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. Informational Identity Analytics XDR Agent Discovery, Credential Access
Analytics SCCM log files enumeration Multiple local SCCM logs were accessed within a short period of time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Storage enumeration activity An identity attempted to discover cloud objects within storage buckets. This might be an attempt by an adversary to find sensitive data stored in cloud storage, which could lead to data theft. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Discovery
Analytics Suspicious Azure enumeration activity An Azure identity performed resource enumeration across multiple services using Microsoft Graph. Medium Cortex Cloud Azure Audit Log, Microsoft Graph Logs Discovery
Analytics Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. Informational Platform Analytics XDR Agent Discovery
Analytics Suspicious reconnaissance using LDAP A process executed multiple suspicious LDAP search queries. This may be indicative of LDAP enumeration. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery
Analytics Unusual multi-region AWS Resource Explorer searches An identity performed unusual discovery activity in multiple regions using Resource Explorer's Search operation. Informational Cortex Cloud AWS Audit Log Discovery
Analytics User and Group Enumeration via SAMR The endpoint performed unfamiliar SAMR querying activity to a domain controller. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Discovery