Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

20 detectors match the current filters. tactic: TA0040 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Abnormal Allocation of compute resources in multiple regions An identity allocated an unusual compute resource pool, suspected as mining activity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Impact, Initial Access
Analytics Allocation of multiple cloud compute resources An identity allocated multiple compute resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact, Initial Access
Analytics An internal Cloud resource performed port scan on external networks An internal cloud resource attempted to connect to the same destination port of multiple external IP addresses. This may be a result of the cloud resource being hijacked by an attacker. Attackers perform port scans on a specific destination port for reconnaissance purposes, to detect known vulnerable services that accept connections in the specific port, and perform targeted attacks against them. Medium Cortex Cloud XDR Agent Discovery, Impact
Analytics Deletion of multiple cloud resources An identity deleted multiple cloud resources. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Logs were not collected from a data source for an abnormally long time Logs were not collected from a data source for an abnormally long time. Low Platform Analytics Health Monitoring Data Impact
Analytics Massive files deletion in Box A user deleted a large amount of data in Box. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Box Audit Log Impact
Analytics Massive files deletion in Dropbox A user deleted a large amount of data in Dropbox. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) DropBox Impact
Analytics Massive files deletion in Google Drive A user deleted a large amount of data in Google Drive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Google Workspace Audit Logs Impact
Analytics Massive files deletion in Microsoft SharePoint or OneDrive A user deleted a large amount of data in Microsoft SharePoint or OneDrive. This behavior may indicate that the data is being wiped. Informational Identity Threat Detection (ITDR) Office 365 Audit Impact
Analytics ML artifacts destruction An identity deleted multiple ML artifacts. Low Cortex Cloud AWS Audit Log, Gcp Audit Log Impact
Analytics Multiple Azure AD admin role removals An Azure AD identity removed multiple administrators from their roles. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Impact
Analytics Multiple user accounts were deleted A user deleted multiple user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Impact
Analytics Possible Insider Threat Activity A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. Low Identity Threat Detection (ITDR) AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH) Impact
Analytics Potential denial of wallet abusing AI services An ML model experienced a sudden spike in requests in a short time. MITRE ATLAS Techniques: AML.T0029 - Denial of ML Service, AML.T0034 - Cost Harvesting. OWASP Top 10 LLM Technique: LLM10 - Unbounded Consumption. Low Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Impact
Analytics Spam Bot Traffic The endpoint connected to an excessive number of external SMTP servers. A spambot may be trying to send spam email using multiple SMTP servers. Spambots can cause your domain to be blacklisted, and can contain other malicious functionality. The same mechanism can also be used for exfiltration. Some VPN clients can also tunnel data over SMTP. Note: This detection model looks for SMTP connections to external servers, but the volume of traffic is not considered. A count is performed based on the number of domains being contacted, as well as the number of unresolved IP addresses. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Impact
Analytics Suspicious EBS snapshots deletion An identity deleted multiple EBS snapshots from the project, considerably more than usual. Low Cortex Cloud AWS Audit Log Impact
Analytics Suspicious ICMP traffic that resembles smurf attack ICMP smurf attack was used. Low Platform Analytics XDR Agent Impact
Analytics Suspicious objects encryption in an AWS bucket An AWS KMS key from a non-organization account was used to encrypt multiple objects in a bucket for the first time. This may indicate an attacker attempting to perform a ransomware attack against the organization's cloud environment. High Cortex Cloud AWS Audit Log Impact
Analytics Suspicious theme and sentiment in email The email's body has a theme and sentiment that may indicate a malicious attempt. Informational Email Security Box Audit Log, DropBox, Google Workspace Audit Logs, Microsoft 365 Emails, Office 365 Audit, Okta Audit Log Impact
Analytics Unusual AWS S3 objects deletion An identity deleted multiple S3 bucket objects from the project, considerably more than usual. Informational Cortex Cloud AWS Audit Log Impact