Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
26 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Cloud DB instance was exported to an unknown destination A Cloud DB instance was exported to a foreign storage destination. The destination storage has not been seen in the organization in the last 30 days. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | A cloud storage object was copied to a foreign cloud account A cloud storage object was copied or moved to a foreign cloud storage account. The destination account was either not monitored or not seen within your tenant for the last 30 days. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log | Exfiltration |
| Analytics BIOC | A GCP Cloud SQL DB instance was exported from a production account A GCP Cloud SQL DB instance was exported to a storage bucket. The DB instance was exported from a production account. | Informational | Cortex Cloud | Gcp Audit Log | Exfiltration |
| Analytics BIOC | An Azure SQL database was exported from a production subscription An Azure SQL database export was initiated. The database was exported from a production subscription. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated An identity generated a SAS URL for an Azure VM snapshot. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An Azure VM snapshot SAS URL was generated for export from a production subscription A SAS URL for an Azure VM snapshot was generated. The operation was performed within a production subscription. SAS URLs allow others to download or export the snapshot. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity initiated a download of multiple cloud objects An identity initiated a download of multiple cloud objects. This might be an indication for an adversary trying to exfiltrate data from cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics | An identity performed a suspicious download of multiple cloud storage objects An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An RDS snapshot containing sensitive data was exported An RDS snapshot containing sensitive data was exported to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported from a production account An RDS snapshot was exported from a production account to an S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An RDS snapshot was exported to an unknown bucket An RDS snapshot was exported to an unknown S3 bucket. The destination bucket has not been seen in your tenant in the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An S3 replication policy to an unknown bucket was created An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days. | Low | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | AWS data asset shared public A data asset was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | AWS S3 bucket was exposed to public access AWS S3 bucket was publicly shared. | Low | Cortex Cloud | AWS Audit Log | Defense Evasion |
| Analytics BIOC | Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. | Informational | Cortex Cloud | Azure Audit Log | Defense Evasion, Privilege Escalation, Initial Access |
| Analytics BIOC | Azure storage account cross-tenant object replication was enabled Azure cross-tenant object replication in a storage account was enabled. | Informational | Cortex Cloud | Azure Audit Log | Exfiltration |
| Analytics BIOC | Cloud snapshot of a database or storage instance was publicly shared A cloud identity has publicly shared a snapshot of a database or storage instance. | Medium | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics | Data exfiltration from cloud database An identity tries to exfiltrate data from cloud database, as indicated by multiple signals. | Low | Cortex Cloud | Azure Audit Log, Gcp Audit Log | Exfiltration, Collection |
| Analytics BIOC | Foreign account was granted permissions to S3 bucket via resource-based policy Foreign account was granted access to S3 bucket. | Informational | Cortex Cloud | AWS Audit Log | Exfiltration |
| Analytics | Multiple cloud snapshots export A cloud identity has downloaded multiple virtual machines or DB snapshots locally. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration |
| Analytics | Suspicious access to Kubernetes API with kubelet credentials A combination of signals has been detected indicating that kubelet credentials were used inside a pod to access the Kubernetes API. This activity suggests an attempt to escalate privileges or move laterally within the cluster. | Low | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Exfiltration, Collection |
| Analytics | Suspicious identity downloaded multiple objects from a bucket An identity downloaded multiple objects from a bucket, considerably more than usual. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |