Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters. technique: T1074 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user connected a new USB storage device to multiple hosts A user connected a new USB storage device to multiple endpoints. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics A user performed suspiciously massive file activity A user generated massive file activity by size or distinct file count. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics A user took numerous screenshots A user took numerous screenshots. A valuable organization's information may have been collected in this way. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Massive file activity abnormal to process A user generated massive file activity by size or distinct file count. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Massive file compression by user Multiple archive files were created by a user. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Massive upload to SaaS service A user uploaded a large amount of data to an organizational cloud storage. This behavior may indicate that the data is being exfiltrated or staged. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Box Audit Log, DropBox, Google Workspace Audit Logs, Office 365 Audit Exfiltration, Collection
Analytics Outlook files accessed by an unsigned process An attacker may use an uncommon and unsigned process to access Outlook data files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics Possible data exfiltration over a USB storage device A process generated massive file creation, renaming and write activity to a USB storage device. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics Possible internal data exfiltration over a USB storage device A user generated abnormal massive file activity to a connected USB storage device. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics User collected remote shared files in an archive Multiple files from remote shares were archived in a local file. This may indicate collection of data and staging before exfiltration. Low Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection