Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

5 detectors match the current filters. tactic: TA0011 ✕ technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. High Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Command and Control
Analytics BIOC A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. High Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access, Command and Control
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Suspicious API call from a Tor exit node A cloud API was called from a Tor exit node. High Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Command and Control, Initial Access