Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
4 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An identity started an AWS SSM session An identity started an AWS SSM interactive session. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement |
| Analytics BIOC | AWS SSM send command attempt An identity executed an AWS SSM Document. | Informational | Cortex Cloud | AWS Audit Log | Lateral Movement, Execution |
| Analytics | Suspicious access to cloud credential files A process accessed multiple cloud credential files, which may indicate a credential theft activity. | Informational | Cortex Cloud | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics BIOC | Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Lateral Movement |