Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

136 detectors match the current filters. technique: T1078 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A cloud identity executed an API call from an unusual country A cloud identity that normally connects from a limited set of countries connected from a new country for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A cloud identity had escalated its permissions A cloud identity had updated its permissions. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Privilege Escalation
Analytics BIOC A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Persistence
Analytics BIOC A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. Low Cortex Cloud Gcp Audit Log Initial Access, Credential Access
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. Informational Cortex Cloud AWS Audit Log Initial Access, Credential Access
Analytics BIOC A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC A disabled user attempted to authenticate via SSO A disabled user attempted to authenticate via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access
Analytics BIOC A disabled user attempted to log in A disabled user attempted to log in. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A disabled user attempted to log in to a VPN A disabled user attempted to log in suspiciously to a VPN. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC A Google Workspace identity created, assigned or modified a role A Google Workspace identity created, assigned or modified a delegated admin role. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Google Workspace identity performed an unusual admin console activity A Google Workspace identity performed an admin console activity for the first time. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Persistence
Analytics BIOC A Kubernetes API operation was successfully invoked by an anonymous user An unauthenticated user successfully invoked API calls within the Kubernetes cluster. Medium Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes ConfigMap was created or deleted A Kubernetes ConfigMap was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A Kubernetes node service account activity from external IP A Kubernetes node service account was seen operating from an external IP. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC A Kubernetes service account was created or deleted A Kubernetes service account was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence
Analytics BIOC A machine certificate was issued with a mismatch A machine certificate was issued with a mismatch between the requester and the subject. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC A possible risky login to Azure A risky sign-in attempt was observed in Azure. Informational Identity Analytics AzureAD Initial Access, Resource Development
Analytics BIOC A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Collection
Analytics BIOC A rare local administrator login A rare local administrator login was observed. This may indicate an attempt to change sensitive settings on the host. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC A Service Principal was created in Azure A Service Principal was created in Azure. This could indicate a malicious actor attempting to gain access to a resource. Informational Cortex Cloud Azure Audit Log Initial Access, Privilege Escalation
Analytics BIOC A Successful login from TOR A successful login from a TOR exit node. High Identity Analytics XDR Agent Initial Access, Command and Control
Analytics BIOC A successful SSO sign-in from TOR A successful sign-in from a TOR exit node. High Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Command and Control
Analytics BIOC A Successful VPN connection from TOR A successful VPN connection from a TOR exit node. High Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access, Command and Control
Analytics BIOC A third-party application was authorized to access the Google Workspace APIs A domain administrator authorized a third-party application to access the Google Workspace APIs. This allows the application to interact with the domain user's data within the authorized scope, as specified in the API call. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Initial Access, Privilege Escalation
Analytics BIOC A user accessed Okta's admin application An attempt to access Okta's admin management application. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access, Persistence, Privilege Escalation
Analytics BIOC A user account was modified to password never expires A user account was modified to password never expires. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation, Credential Access
Analytics BIOC A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access, Persistence
Analytics BIOC A user logged in at an unusual time via SSO A user connected via SSO on a day and hour that is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Defense Evasion
Analytics BIOC A user logged in at an unusual time via VPN A user connected to a VPN on a day and hour, which is unusual for this user. This may indicate that the account was compromised. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics BIOC A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Lateral Movement
Analytics BIOC A user was added to a Windows security group A user was added to a Windows security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Abnormal User Login to Domain Controller A user account has successfully logged on to a Domain Controller (DC), generating a Windows Event Log. This may be a sign of DC and Active Directory (AD) compromise. Informational Identity Analytics XDR Agent Lateral Movement, Privilege Escalation
Analytics BIOC Admin privileges were granted to a Google Workspace user Admin privileges were granted to a Google Workspace user. This user now has access to additional administrative functions and settings. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Google Workspace Audit Logs Privilege Escalation
Analytics BIOC An AWS database service master user password was changed An AWS database service master user password was changed. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An AWS EKS cluster was created or deleted An AWS EKS cluster has been created or deleted. Informational Cortex Cloud AWS Audit Log Initial Access, Impact
Analytics BIOC An Azure Kubernetes Role or Cluster-Role was modified An Azure Kubernetes Role or Cluster-Role was modified or deleted. This could indicate malicious activity and should be investigated. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted. This could indicate a security breach or malicious activity. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An Email address was added to AWS SES An Email address was added to AWS SES. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC An identity was granted permissions to manage user access to Azure resources An identity was granted the User Access Administrator permission at the tenant scope. Informational Cortex Cloud Azure Audit Log Privilege Escalation
Analytics BIOC An inactive user attempted to authenticate A user with no activity in the past 30 days with the target, attempted to authenticate via universal authentication. Informational Identity Analytics Initial Access
Analytics BIOC Authentication attempt by a honey user An authentication attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics AzureAD, Okta, OneLogin, PingOne Initial Access
Analytics BIOC Authentication Attempt From a Dormant Account A dormant user account tried to authenticate to a service using a TGS after having been unused for a year or more. This may indicate the account is misused by an attacker. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC Authentication method added to an Azure account An identity attempted to add an Azure authentication method. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC AWS console login without MFA An identity logged in to the AWS console without MFA. Informational Cortex Cloud AWS Audit Log Initial Access, Persistence, Credential Access
Analytics BIOC AWS root account activity The AWS root account has successfully performed an operation in the project. Informational Cortex Cloud AWS Audit Log Initial Access
Analytics BIOC AWS SES account sending settings modified AWS SES account sending settings were modified. Informational Cortex Cloud AWS Audit Log Persistence
Analytics BIOC AWS STS temporary credentials were generated AWS STS temporary credentials were generated for an AWS identity. Informational Cortex Cloud AWS Audit Log Persistence, Initial Access, Credential Access
Analytics BIOC Azure AD account unlock/password reset attempt An attempt to unlock an Azure AD identity or reset its password has occurred. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC Azure AD PIM elevation request An Azure AD PIM elevation request was denied/approved. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure AD PIM role settings change An identity changed the PIM role settings. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure Automation Account Creation Azure Automation account was created. An attacker might create an account for persistence. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure Automation Runbook Creation/Modification An Azure Automation Runbook was being modified or created. Informational Cortex Cloud Azure Audit Log Persistence
Analytics BIOC Azure group creation/deletion A group in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure service principal assigned app role An identity assigned an app role (permissions) to a service principal. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Privilege Escalation
Analytics BIOC Azure storage account blob anonymous access is enabled It is possible to configure anonymous access to blobs within the storage account. Informational Cortex Cloud Azure Audit Log Defense Evasion, Privilege Escalation, Initial Access
Analytics BIOC Azure Temporary Access Pass (TAP) registered to an account An identity registered an Azure Temporary Access Pass (TAP) to an account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Defense Evasion, Privilege Escalation
Analytics BIOC Azure user creation/deletion A user in Azure was created or deleted. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Azure user password reset The password of an Azure AD user was reset. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Persistence
Analytics BIOC Cloud activity from a high-risk IP address An identity executed a cloud API from a high-risk IP address. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Initial Access, Command and Control
Analytics BIOC Cloud impersonation attempt by unusual identity type A suspicious identity type has attempted to impersonate another identity. Informational Cortex Cloud AWS Audit Log, Gcp Audit Log Initial Access
Analytics BIOC Failed Login For Locked-Out Account A locked-out user account (event ID 4725 or 4740) was used in a Kerberos TGT pre-authentication attempt. Informational Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent Defense Evasion
Analytics BIOC First Azure AD PowerShell operation for a user A user performed an Azure AD operation using a PowerShell user-agent for the first time. Low Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Initial Access
Analytics BIOC First SSO access from ASN for user A user successfully authenticated via SSO with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO access from ASN in organization An SSO authentication was made with a new ASN. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Google Workspace Authentication, Okta, OneLogin, PingOne Initial Access
Analytics BIOC First SSO Resource Access in the Organization A resource was accessed for the first time via SSO. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Discovery
Analytics BIOC First VPN access from ASN for user A user logged in to a VPN with a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC First VPN access from ASN in organization A VPN connection was attempted from a new ASN. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC First-time directory sync of an on-premises domain user to an existing cloud account First-time synchronization of an on-premises domain user with an existing cloud account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Audit Log Persistence
Analytics BIOC FTP Connection Using an Anonymous Login or Default Credentials An FTP connection using an anonymous login was detected. Low Platform Analytics Palo Alto Networks Firewall EAL Logs Initial Access, Credential Access
Analytics BIOC GCP service account impersonation attempt An attempt to impersonate the GCP service account failed. Informational Cortex Cloud Gcp Audit Log Privilege Escalation, Initial Access
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics BIOC IAM User added to an IAM group An IAM user was added to an IAM group. Informational Cortex Cloud AWS Audit Log Privilege Escalation, Persistence
Analytics BIOC Interactive login by a machine account A machine account performed an interactive or remote interactive login. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login by a service account A service account performed an interactive or remote interactive login. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Interactive login from a shared user account A user account has been seen active on multiple hosts. Shared accounts are often considered 'bad practice' and may present multiple security risks to the organization. Informational Identity Analytics XDR Agent Initial Access
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Kubernetes service account activity outside the cluster A service account user successfully invoked API calls outside the Kubernetes cluster. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Initial Access
Analytics BIOC Linux local user account creation A user executed a process associated with user account creation. Informational Identity Analytics XDR Agent Persistence
Analytics BIOC Local user account creation A user was observed creating a rare local user account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Local user account creation by a machine account A machine account was observed creating a rare local user account. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Login attempt by a honey user A login attempt was made by a honey user, a decoy account created to detect unauthorized access. This may indicate potential attacker activity attempting to use valid or stolen credentials. Low Identity Analytics XDR Agent Initial Access
Analytics BIOC Login by a dormant user A dormant user logged on after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics XDR Agent Defense Evasion
Analytics BIOC Machine account was added to a domain admins group A machine account was added to a domain admins group. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC Masquerading as a default local account A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection. Low Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Defense Evasion, Persistence
Analytics BIOC Member added to a Windows local security group A member was added to a Windows local security group. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC New FTP Server A new FTP server has been detected. Low Platform Analytics Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls Initial Access, Collection
Analytics BIOC Okta account unlock by admin An administrative user unlocked an Okta account. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Okta Reported Attack Suspected Okta Threat Insight Reported Attack Suspected. Low Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Initial Access
Analytics BIOC Owner was added to Azure application An Owner was added to an Azure application. Informational Cortex Cloud Azure Audit Log, Microsoft Graph Logs Privilege Escalation, Persistence
Analytics BIOC PKINIT TGT authentication request A Kerberos TGT was requested using PKINIT. This may indicate an attack on Active Directory Certificate Services (AD CS), such as shadow credential exploitation or certificate-based authentication abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Lateral Movement, Privilege Escalation
Analytics BIOC Potential Okta access limit breach A user surpassed Okta's rate limit, leading to an access limit violation. This could suggest a potential account takeover attempt. Informational Identity Threat Detection (ITDR), SaaS Threat Detection Okta Audit Log Collection, Initial Access
Analytics BIOC Privileged certificate request via certificate template A privileged certificate was requested via certificate template. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation
Analytics BIOC PsExec was executed with a suspicious command line PsExec.exe was executed. Informational Platform Analytics XDR Agent Execution, Privilege Escalation
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics BIOC Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. Informational Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics BIOC Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. Medium Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Persistence