Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
34 detectors match the current filters. technique: T1110 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A user rejected an SSO request from an unusual country A user rejected an SSO authentication request from an abnormal country. | Low | Identity Analytics | Okta, OneLogin | Credential Access, Resource Development |
| Analytics | Account probing A user failed to log in to multiple hosts it never accessed before in a short amount of time. This may indicate the account is compromised and an attacker is probing for a host it can access with those credentials. | Low | Identity Analytics | XDR Agent | Initial Access, Credential Access |
| Analytics | Brute-force attempt on a local account A local user account failed to log in multiple times in a short time period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Excessive user account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | External Login Password Spray An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Impossible traveler - SSO User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. | Low | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics | Impossible traveler - VPN A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. | Low | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access, Resource Development |
| Analytics | Intense SSO failures An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Initial Access |
| Analytics | Interactive local account enumeration Multiple non-existing accounts attempted interactive local logins to a host within a short period. This may indicate that an attacker has physical access to the host and is trying to enumerate accounts. | Low | Identity Analytics | XDR Agent | Discovery, Credential Access |
| Analytics | Internal Login Password Spray An abnormally high amount of user account login attempts were seen from a host within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | IP Rotation Pattern in SSO Spray A high volume of SSO authentication attempts was observed in a short time window. This behavior may indicate a password spray attack targeting multiple accounts. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics | Kerberos Pre-Auth Failures by Host The endpoint failed an unusual number of Kerberos pre-authentications (TGT requests) from at least three users when compared to its baseline. This can indicate a password-spraying attack. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Kerberos Pre-Auth Failures by User and Host The user account on this host failed Kerberos pre-authentications (TGT requests) an unusual number of times. This can indicate a Kerberos brute-force attack. | Informational | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Multiple Suspicious FTP Login Attempts Multiple suspicious FTP sessions were detected, which may indicate a brute-force attempt. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Credential Access |
| Analytics | Multiple user accounts failed login due to account lockouts A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Brute Force A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Brute Force on a Service Account A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Brute Force on an Administrator Account An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | NTLM Password Spray A single host tried to perform an unusual amount of login attempts using NTLM in a short period of time. This may be indicative of a NTLM password spray attack. | Informational | Identity Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent | Credential Access |
| Analytics | Possible Brute Force in universal authentication An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack. | Informational | Identity Analytics | Credential Access, Resource Development | |
| Analytics | Possible brute force on sudo user A user executed an unusual amount of sudo commands in a short time period. This may indicate an attempt to guess the sudo password. | Informational | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible brute force or configuration change attempt on cytool An unusual amount of cytool commands were executed in a short period from a user who doesn't usually run these commands. This may indicate an attempt to guess the Administrator password. | High | Platform Analytics | XDR Agent | Credential Access |
| Analytics | Possible Brute-Force attempt A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack. | Informational | Identity Analytics | XDR Agent | Credential Access, Lateral Movement |
| Analytics | Possible external RDP Brute-Force Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. | Low | Identity Analytics | XDR Agent | Credential Access |
| Analytics | Possible Password Spray in universal authentication An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack. | Informational | Identity Analytics | Credential Access, Resource Development | |
| Analytics | Remote account enumeration Multiple non-existing accounts failed to remotely log in to a host in a short period of time. This may indicate an attacker is trying to remotely enumerate accounts. | Informational | Identity Analytics | XDR Agent | Discovery, Credential Access |
| Analytics | Single account excessively locked out A user has been locked out an unusually high number of times within a short timeframe. This could indicate an attempt to gain unauthorized access to the user's account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | SSH authentication brute force attempts A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. | Informational | Identity Analytics | XDR Agent | Credential Access |
| Analytics | SSO Brute Force An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics | SSO Password Spray An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. | Informational | Identity Analytics | AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne | Credential Access, Resource Development |
| Analytics | Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics | Suspicious Kerberos Pre-Auth Failures by Host An endpoint failed unusual number of Kerberos pre-authentications (TGT requests) which may indicate a password-spraying attack. | Low | Identity Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Credential Access |
| Analytics | VPN login Brute-Force attempt A user account failed to log in to a VPN service multiple times in a short time period. This may indicate a brute-force attack. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access, Resource Development |
| Analytics | VPN Login Password Spray An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack. | Informational | Identity Analytics | Palo Alto Networks Global Protect, Third-Party VPNs | Credential Access |