Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
88 detectors match the current filters. technique: T1098 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity had escalated its permissions A cloud identity had updated its permissions. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Privilege Escalation |
| Analytics BIOC | A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | A computer account was promoted to DC A computer account was promoted to a domain controller via a User Account Control (UAC) change. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | A Google Workspace user was added to a group A user added another user to a Google Workspace group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | A Kubernetes cluster role binding was created or deleted A Kubernetes cluster role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A Kubernetes cluster role was created A Kubernetes cluster role was created. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Persistence, Privilege Escalation |
| Analytics BIOC | A Kubernetes role binding was created or deleted A Kubernetes role binding was created or deleted. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Privilege Escalation |
| Analytics BIOC | A process modified an SSH authorized_keys file A process modified an SSH authorized_keys file, which is used in SSH authentication. An attack can add or remove an SSH key to gain access to a targeted host. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | A user accessed Okta's admin application An attempt to access Okta's admin management application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Initial Access, Persistence, Privilege Escalation |
| Analytics BIOC | A user certificate was issued with a mismatch A certificate was issued to a user who was not the requester, this may indicate a certificate manipulation. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation, Credential Access |
| Analytics BIOC | A user enabled a default local account A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Initial Access, Persistence |
| Analytics BIOC | A user logged in to the AWS console for the first time A user logged in to the AWS console for the first time. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Lateral Movement |
| Analytics BIOC | A user was added to a Windows security group A user was added to a Windows security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | An identity attached an administrative policy to an IAM user or role An identity attached an administrative policy to an IAM user or role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An identity created or updated password for an IAM user An identity created or updated an AWS console password for an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | An unknown account was invited to the AWS organization An unknown account was invited to your AWS organization. The target account was not seen in your tenant for the last 30 days. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS console login without MFA An identity logged in to the AWS console without MFA. | Informational | Cortex Cloud | AWS Audit Log | Initial Access, Persistence, Credential Access |
| Analytics BIOC | AWS IAM Role Created with Cross-Account Access A cloud identity has created a new IAM role with trust policy that allows external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access A cloud identity has updated an IAM role's trust policy to allow external AWS account access. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS Lambda Cross-Account sensitive permissions configured A cloud identity has granted external AWS account sensitive permissions to a Lambda function. | Low | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS support case creation A cloud identity has created a new case in AWS support. | Informational | Cortex Cloud | AWS Audit Log | Discovery, Privilege Escalation |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Azure application credentials added An identity added credentials to an Azure application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure application URI modification An identity added or updated an Azure application's URI. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure Automation Webhook creation Azure Automation Webhook can be used to pass a payload with specific attributes to run a malicious Runbook. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure device code authentication flow used An Azure AD login was performed with device code flow. | Informational | Identity Analytics | Azure Audit Log | Defense Evasion, Persistence |
| Analytics BIOC | Azure domain federation settings modification attempt A user or application attempted to modify the federation settings of the domain. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Azure group creation/deletion A group in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure permission delegation granted An identity delegated permissions to access a certain resource or application. | Informational | Cortex Cloud | Azure Audit Log | Persistence |
| Analytics BIOC | Azure Service principal/Application creation An Azure Service principal/Application was created. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure user creation/deletion A user in Azure was created or deleted. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure user password reset The password of an Azure AD user was reset. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence |
| Analytics BIOC | Azure VM extension abuse attempt A suspicious Azure VM extension operation was detected. Attackers can use CustomScriptExtension to execute arbitrary scripts on VMs, VMAccessExtension to reset local passwords for persistence, or delete the IaaSAntimalware extension to disable antimalware protection and evade detection. | Informational | Cortex Cloud | Azure Audit Log | Execution, Persistence, Defense Evasion |
| Analytics BIOC | Cloud access key creation Cloud access key creation by a cloud identity. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Credentials were added to Azure application Credentials were added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | Exchange mailbox folder permission modification A user modified permissions to an Exchange mailbox folder. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Persistence |
| Analytics BIOC | External user invitation to Azure tenant An external user was invited to Azure tenant. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Persistence, Privilege Escalation |
| Analytics BIOC | GCP administrative role granted to a cloud identity A cloud identity granted an administrative IAM role to another identity. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Cloud Run role granted A cloud identity granted itself a sensitive Cloud Run IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive compute role granted A cloud identity granted itself a sensitive compute IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Deployment Manager role granted A cloud identity granted itself a sensitive Deployment Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Functions role granted A cloud identity granted itself a sensitive Functions IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive IAM role granted A cloud identity granted itself a sensitive IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive role granted to group A cloud identity granted a sensitive role to a group. | Low | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive Secret Manager role granted A cloud identity granted itself a sensitive Secret Manager IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP sensitive storage role granted A cloud identity granted itself a sensitive storage IAM role. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | GCP Service Account key creation A GCP service account key was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics BIOC | GCP set IAM policy activity A cloud identity had modified a resource policy bindings. | Informational | Cortex Cloud | Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Google Workspace organizational unit was modified A Google Workspace admin modified an organizational unit. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Persistence |
| Analytics BIOC | Google Workspace user authentication information changed Google Workspace authentication information was changed for a user. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Credential Access, Persistence |
| Analytics BIOC | IAM inline policy was added to group A cloud identity added an AWS IAM inline policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to role A cloud identity added an AWS IAM inline policy to an IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM inline policy was added to user A cloud identity added an AWS IAM inline policy to an IAM user. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM instance profile was associated with EC2 instance An AWS IAM instance profile was associated with EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was created An AWS IAM instance profile was created. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM instance profile was replaced for EC2 instance An AWS IAM instance profile was replaced for EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM policy default version was changed A cloud identity set the specified version of an AWS IAM policy as the policy's default. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy version was created A cloud identity created an AWS-managed IAM policy version. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to group A cloud identity attached an AWS IAM policy to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM policy was attached to role An AWS IAM policy was attached to this role. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | IAM role trust policy modification A cloud identity updated the trust policy of an AWS IAM role. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM role was created An IAM role was created. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | IAM User added to an IAM group An IAM user was added to an IAM group. | Informational | Cortex Cloud | AWS Audit Log | Privilege Escalation, Persistence |
| Analytics BIOC | Identity assigned an Azure AD Administrator Role An identity was assigned an Azure AD Administrator role. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | Member added to a Windows local security group A member was added to a Windows local security group. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Privilege Escalation |
| Analytics BIOC | New Teams application published to the organization catalog A new Teams application was published to the organization catalog. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | Okta admin privilege assignment A user assigned admin privileges to a new user or group. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation |
| Analytics BIOC | Okta API Token Created A user created a new API token in Okta. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Privilege Escalation, Execution, Persistence |
| Analytics BIOC | Owner was added to Azure application An Owner was added to an Azure application. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Privilege Escalation, Persistence |
| Analytics BIOC | Potential creation of persistent cloud credentials A cloud identity invoked a credential-related persistence operation. | Informational | Cortex Cloud | AWS Audit Log | Persistence, Credential Access, Lateral Movement |
| Analytics BIOC | Privileged role used by Azure application An Azure application with high-level API permissions invoked a request to the Microsoft Graph API. | Low | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Privilege Escalation |
| Analytics BIOC | Service ticket request with a spoofed sAMAccountName A Kerberos service ticket (ST) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | SharePoint Site Collection admin group addition A user made an addition to the site collection administrators group in SharePoint. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Persistence |
| Analytics BIOC | SPNs cleared from a machine account Service principal names were cleared from a machine account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious account attribute modification that matches that of another account Suspicious account attribute modification that matches that of another account. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious cloud compute instance SSH keys modification attempt An identity attempted to modify the SSH keys of a single compute instance. This may indicate an attacker's attempt to maintain persistence on the cloud instance. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence, Lateral Movement |
| Analytics BIOC | Suspicious dNSHostName attribute change to DC name The dNSHostName attribute of a machine account was changed to a Domain Controller server name. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | Suspicious modification of the AdminSDHolder's ACL A user modified the AdminSDHolder ACL, which may be an indication of a privilege escalation attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious sAMAccountName change The name of a machine account was changed to a sAMAccountName with a missing trailing dollar sign. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | TGT request with a spoofed sAMAccountName - Event log A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Privilege Escalation, Persistence |
| Analytics BIOC | TGT request with a spoofed sAMAccountName - Network A Kerberos authentication ticket (TGT) was requested for an account with a spoofed sAMAccountName. | Medium | Identity Analytics | XDR Agent | Privilege Escalation, Persistence |
| Analytics BIOC | Unusual AWS credentials creation AWS utility was used to create an access key and a secret key. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual AWS user added to group AWS user added to AWS group, possibly to elevate privileges and gain more access to resources. | Low | Platform Analytics | XDR Agent | Persistence |
| Analytics BIOC | Unusual Identity and Access Management (IAM) activity A cloud identity performed an unusual IAM operation. | Informational | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence, Privilege Escalation |
| Analytics BIOC | Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Unverified domain added to Azure AD A new unverified domain was added to Azure AD. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | User account delegation change A user account was modified with delegation to a service. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | User added a new device to Okta Verify instance The user has successfully registered a new device with the Okta Verify application. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Okta Audit Log | Persistence |