Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

8 detectors match the current filters. technique: T1074 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A user connected a new USB storage device to a host A user connected a new USB storage device that was not seen for this user and host in the last 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user connected a USB storage device for the first time A user connected a USB storage device for the first time in the past 30 days. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection, Exfiltration
Analytics BIOC A user created an abnormal password-protected archive A user created an abnormal password-protected archive using an archive program. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC An unusual archive file creation by a user An archive file was created by a user who doesn't usually create such files. This might indicate an attempt to stage data before exfiltration. Informational Identity Threat Detection (ITDR) XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC Gmail routing settings changed Gmail routing settings were modified. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Collection
Analytics BIOC Mailbox Client Access Setting (CAS) changed An attacker may use PowerShell to change the Client Access Settings (CAS) for a mailbox, hence gaining access to the data. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection
Analytics BIOC OneDrive folder creation A folder was created in OneDrive using Microsoft Graph API. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Collection
Analytics BIOC PowerShell used to export mailbox contents An attacker may use PowerShell to export the contents of a mailbox as part of the data staging before exfiltration. Medium Platform Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Collection