Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

62 detectors match the current filters. tactic: TA0010 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Backup vault policy was modified A cloud identity has modified backup vault access policy. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A Cloud DB instance was exported to an unknown destination A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. Medium Cortex Cloud AWS Audit Log, Azure Audit Log Exfiltration
Analytics BIOC A compressed file was exfiltrated over SSH Exfiltration of a compressed file over SSH. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC A GCP Cloud SQL DB instance was exported from a production account A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC A mail forwarding rule was configured in Google Workspace A rule was set up to forward emails outside the Google Workspace domain. Medium Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection, Exfiltration
Analytics BIOC A process connected to a rare cloud resource A process connected to a rare cloud resource. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC A Torrent client was detected on a host The host produced traffic consistent with the BitTorrent protocol. Torrent usage may expose the organization to malware or enable attackers or malicious insiders to exfiltrate data. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration, Initial Access
Analytics BIOC A user accessed an uncommon AppID A user accessed an uncommon AppID that is rarely accessed by them or anyone else in the organization. Informational Identity Threat Detection (ITDR) Palo Alto Networks Firewall EAL Logs, Palo Alto Networks Firewall threat Logs, Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration
Analytics BIOC A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC Abnormal communication with a rare combination of TLS and HTTP User Agent Abnormal communication with a rare combination of TLS and HTTP User Agent to an external address. Low Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server to an external address. Informational Platform Analytics Palo Alto Networks Firewall EAL Logs, XDR Agent Command and Control, Exfiltration
Analytics BIOC An AWS EC2 instance containing sensitive data was exported A EC2 instance was exported to an S3 bucket. The instance was found to contain sensitive data. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EC2 instance was exported from a production account An EC2 instance was exported from a production account to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS EC2 instance was exported into an unknown S3 bucket An EC2 instance was exported to an unknown S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An Azure SQL database was exported from a production subscription An Azure SQL database export was initiated. The database was exported from a production subscription. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC An Azure VM snapshot SAS URL was generated An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC An Azure VM snapshot SAS URL was generated for export from a production subscription A SAS URL for an Azure VM snapshot was generated. The operation was performed within a production subscription. SAS URLs allow others to download or export the snapshot. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. Informational Cortex Cloud AWS Audit Log Collection, Exfiltration
Analytics BIOC An identity accessed a backup cloud storage An identity accessed a backup cloud storage. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An RDS snapshot was exported to an unknown S3 bucket An RDS snapshot was exported to an S3 bucket. The destination S3 bucket was not seen in your organization in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An unusual cloud identity was granted permissions to a BigQuery resource An unusual cloud identity was granted permissions to a BigQuery table or dataset. Informational Cortex Cloud Gcp Audit Log Exfiltration, Defense Evasion
Analytics BIOC An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Collection, Exfiltration
Analytics BIOC AWS EC2 instance exported into S3 A running or stopped instance was exported to an Amazon S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC AWS network ACL rule creation An AWS network ACL rule was created with a specific rule number. Informational Cortex Cloud AWS Audit Log Persistence, Exfiltration
Analytics BIOC AWS Transfer Family server created A cloud identity created server using AWS Transfer Family service. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. Informational Cortex Cloud Azure Audit Log Exfiltration
Analytics BIOC Bedrock model shared with a foreign account A bedrock model was shared with a foreign account through AWS resource access manager. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC BigQuery table or query results exfiltrated to a foreign project A cloud identity exfiltrated BigQuery table data to a foreign storage service. Informational Cortex Cloud Gcp Audit Log Exfiltration
Analytics BIOC Bucket's block public access setting turned off S3 bucket block public access setting turned off. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Bucket's object ownership controls were modified S3 bucket object ownership controls were modified. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. Medium Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Commonly abused AutoIT script connects to an external domain AutoIT scripts have legitimate uses, but are often abused by malware to execute in a signed process context. Medium Platform Analytics XDR Agent Exfiltration, Execution
Analytics BIOC EC2 instance Amazon machine image was created Amazon machine image was created from elastic compute cloud instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Exchange inbox forwarding rule configured A user configured an Exchange inbox forwarding rule, which forwards emails that meet specific conditions. Informational Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange transport forwarding rule configured A user configured an Exchange transport (mail flow) forwarding rule, which is applied to all emails that match certain conditions in the organization. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC Exchange user mailbox forwarding A user configured Exchange SMTP forwarding on a mailbox, which forwards all emails sent to that mailbox to a specified recipient. Low Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security Office 365 Audit Collection, Exfiltration
Analytics BIOC External Sharing was turned on for Google Drive An identity has modified Google Drive sharing settings and allowed external sharing. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Exfiltration
Analytics BIOC First-seen email from mailbox owner to external recipient's address in the last 30 days Internal sender initiated first-time communication with an external recipient in the last 30 days. Informational Email Security Microsoft 365 Emails Exfiltration
Analytics BIOC Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Google Workspace automation was created Google Workspace automation was created. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Execution, Persistence, Exfiltration
Analytics BIOC Microsoft Teams external communication policy was modified Microsoft Teams external communication policy was modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Office 365 Audit Defense Evasion, Exfiltration
Analytics BIOC Possible IPFS traffic was detected The host attempted to access other nodes in an IPFS manner. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Possible use of IPFS was detected The host produced traffic consistent with IPFS. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Exfiltration, Initial Access
Analytics BIOC Python HTTP server started Python HTTP server started - possible exfiltration over HTTP. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Rare SMTP/S Session The Simple Mail Transfer Protocol (SMTP) and its SSL-secured variant SMTPS are used to send email. Attackers can use SMTP/S to exfiltrate data from your network. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Exfiltration
Analytics BIOC Rare Unix process divided files by size A file was divided into sub-files by size limit by a rare process. Informational Platform Analytics XDR Agent Exfiltration
Analytics BIOC Sending unusual file(s) to an external address Unusual files sent to an external address. Low Email Security Microsoft 365 Emails Initial Access, Exfiltration
Analytics BIOC Suspicious Network Connection Originating from AWS SSM Agent A process spawned by the AWS SSM agent connected to an anonymous tunnel or TOR IP outside AWS. This may indicate the SSM agent was abused for command and control or data exfiltration. Medium Cortex Cloud XDR Agent Command and Control, Exfiltration
Analytics BIOC Uncommon AppleScript was executed via the command line to contact an external server The AppleScript interpreter executed a script designed to contact an external server. Low Platform Analytics XDR Agent Execution, Exfiltration
Analytics BIOC Uncommon recurring rare external host access A process has established recurring connections to an uncommon external host. Informational Platform Analytics XDR Agent Command and Control, Exfiltration
Analytics BIOC User signed in to an application via Power Automate for the first time A user signed in to an application via Power Automate for the first time. This may be indicative of a compromised account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Exfiltration
Analytics BIOC WebDAV drive mounted from net.exe over HTTPS Attackers may mount a WebDAV drive over HTTPS to upload files to and download files from a compromised machine. Informational Platform Analytics XDR Agent Exfiltration