Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

15 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Backup vault policy was modified A cloud identity has modified backup vault access policy. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud snapshot of AWS database or storage was modified or shared A cloud identity has shared a snapshot of an AWS database or storage instance. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC A cloud storage configuration was modified A cloud storage configuration was modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Defense Evasion
Analytics BIOC A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. Medium Cortex Cloud AWS Audit Log, Azure Audit Log Exfiltration
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS RDS instance was created from a snapshot A new AWS RDS instance was created from a publicly available RDS snapshot. Informational Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC An AWS S3 bucket configuration was modified An AWS S3 bucket configuration has been modified. Informational Cortex Cloud AWS Audit Log Defense Evasion, Impact
Analytics BIOC An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. Low Cortex Cloud AWS Audit Log Exfiltration
Analytics BIOC Azure Blob Container Access Level Modification Access level modification for a blob container, this action might be dangerous as sensitive data can be exposed. Informational Cortex Cloud Azure Audit Log Defense Evasion
Analytics BIOC Azure Storage Account key generated Azure storage access keys rotation, might affect services/applications depended on the key set. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Exfiltration, Defense Evasion, Collection
Analytics BIOC GCP Storage Bucket Configuration Modification A GCP storage bucket configuration has been modified. Informational Cortex Cloud Gcp Audit Log Impact
Analytics BIOC GCP Storage Bucket Permissions Modification A GCP storage bucket's IAM permissions were modified. An attacker might use this technique to expose sensitive data or cause data loss. Informational Cortex Cloud Gcp Audit Log Defense Evasion
Analytics BIOC S3 configuration deletion An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains. Informational Cortex Cloud AWS Audit Log Impact
Analytics BIOC Soft delete of cloud storage configuration was disabled A Soft Delete configuration was disabled on a cloud storage account. Soft delete allows a deletion of a blob or a container to be restored. Disabling it will impair the ability of the cloud environment to recover in disaster scenarios. Informational Cortex Cloud Azure Audit Log Impact