Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

13 detectors match the current filters. tactic: TA0009 ✕ technique: T1114 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC A mail forwarding rule was configured in Google Workspace A rule was set up to forward emails outside the Google Workspace domain. Medium Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Exfiltration
Analytics BIOC Azure mailbox rule creation A Mailbox rule in Azure was created. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection, Defense Evasion
Analytics BIOC Exchange compliance search created A user created an Exchange compliance search. This feature enables Administrators to search mailboxes in an organization. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Gmail routing settings changed Gmail routing settings were modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Possible Email collection using Outlook RPC Outlook was executed using RPC by an uncommon parent process, this may be an indication of email collection activities. Informational Platform Analytics XDR Agent Collection
Analytics BIOC SAAS - Email was reported by the user or administrator as a phishing attempt An email reported by the user or administrator as a phishing attempt has been detected. Informational Email Security Office 365 Audit Collection
BIOC Scripting process reads Outlook data files Attackers may try to retrieve email data and sensitive information from .ost and .pst files. Informational Platform Analytics File Collection
Analytics Sensitive Exchange mail sent to external users A user sent sensitive email messages to external users. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration