Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. tactic: TA0009 ✕ technique: T1213 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics BIOC OneDrive file download A file was downloaded from OneDrive using the Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics BIOC Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection
Analytics BIOC Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
Analytics User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Collection
BIOC Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. Informational Platform Analytics File Collection