Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. tactic: TA0040 ✕ technique: T1531 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Google Workspace Role privilege was deleted A privilege was removed from a Google Workspace Role, This could potentially affect the access to services and data in the organization. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Impact |
| Analytics BIOC | A Google Workspace user was removed from a group A user removed another user from a Google Workspace group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Impact |
| Analytics BIOC | A third-party application's access to the Google Workspace domain's resources was revoked An identity removed a third-party application's access to Google Workspace domain's resources. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Impact |
| Analytics BIOC | An Azure Kubernetes Service Account was modified or deleted An Azure Kubernetes Service Account was modified or deleted. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | AWS IAM resource group deletion An AWS IAM resource group was deleted, this action may affect the permissions of the members of the deleted group. | Informational | Cortex Cloud | AWS Audit Log | Impact |
| Analytics BIOC | Azure account deletion by a non-standard account An Azure AD account deletion was performed by a user that doesn't typically delete users. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Impact |
| Analytics BIOC | Billing admin role was removed Sensitive Action - Billing admin role was removed. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM deny policy creation An identity created a GCP IAM deny policy. | Low | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Role Deletion A GCP IAM role was created. An attacker might use this technique to interrupt users' actions. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP IAM Service Account Key Deletion A GCP IAM service account key was deleted. An attacker might use this technique to interrupt business operations. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Deletion A GCP service account was deleted. An attacker might use this technique to remove access to valid accounts. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics BIOC | GCP Service Account Disable A GCP service account was disabled. An attacker might use this technique to interrupt business procedures and workflows. | Informational | Cortex Cloud | Gcp Audit Log | Impact |
| Analytics | Multiple Azure AD admin role removals An Azure AD identity removed multiple administrators from their roles. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Impact |
| Analytics | Multiple user accounts were deleted A user deleted multiple user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Impact |
| Analytics BIOC | PIM privilege member removal A cloud identity has removed a user's privileged role within PIM. | Informational | Cortex Cloud | Azure Audit Log | Impact |
| Analytics BIOC | Sensitive account password reset attempt An attempt was made to reset a sensitive account's password. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Impact |