Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
15 detectors match the current filters. technique: T1136 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A cloud identity invoked IAM related persistence operations A cloud identity invoked IAM related persistence operations. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Persistence |
| BIOC | Account creation via command-line tool The useradd/adduser command could be used to create user accounts or to add users to existing groups. | Informational | Platform Analytics | Process execution | Persistence |
| Analytics BIOC | An IAM group was created An IAM group was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | AWS user creation A new AWS user was created. | Informational | Cortex Cloud | AWS Audit Log | Persistence |
| Analytics BIOC | Azure account creation by a non-standard account An Azure AD account creation was performed by a user that doesn't typically create users. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD Audit Log | Persistence |
| Analytics BIOC | GCP Service Account creation A GCP service account was created. An attacker might use this technique to evade detection. | Informational | Cortex Cloud | Gcp Audit Log | Persistence |
| Analytics | Multiple suspicious user accounts were created A user was observed creating multiple rare user accounts. | Low | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics | New cloud identity created with administrative policy New cloud identity was created and assigned administrative policy. | Low | Cortex Cloud | AWS Audit Log, Gcp Audit Log | Persistence |
| Analytics BIOC | Rare machine account creation A user was observed creating a machine account for the first time. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious domain user account creation A user was observed creating a rare domain account. | Informational | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence |
| Analytics BIOC | Suspicious hidden user created A user account was created with a name that mimics a machine account. | Medium | Identity Analytics | Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) | Persistence, Defense Evasion |
| Analytics BIOC | Uncommon net group command execution Uncommon net group command execution which may be used for groups and users enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon net localgroup command execution Uncommon net localgroup command execution which may be used for group and user enumeration and unauthorized user creation. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| Analytics BIOC | Uncommon user management via net.exe The net.exe command is used to add, delete, and otherwise manage the users on a computer. Adversaries may attempt to use the command to discover or add local and domain user accounts. | Informational | Platform Analytics | XDR Agent | Discovery, Persistence |
| BIOC | User creation or modification via /etc file Attackers may create new users or modify existing users by directly modifying /etc/passwd and /etc/shadow. | Informational | Platform Analytics | File | Persistence |