Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
13 detectors match the current filters. technique: T1204 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics | A cloud identity performed multiple unusual activities A cloud identity performed multiple unusual activities across various cloud services. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Execution |
| Analytics | A user uploaded malware to SharePoint or OneDrive A user uploaded a file that was classified as malware to SharePoint or OneDrive. | Low | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Lateral Movement, Execution |
| Analytics | Abnormal increase in network-related alerts on the same host Abnormal increase in network-related alerts on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | AI-determined combination of risky alerts under the same actor process Multiple alerts likely to be associated with an incident were identified under the same actor process. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | AI-determined combination of risky alerts under the same causality Multiple alerts likely to be associated with an incident were identified under the same causality. | Informational | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple alerts of different MITRE tactics were seen Multiple alerts of different MITRE tactics were seen on the same host under the same causality. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts of different MITRE tactics on the same host Multiple alerts of different MITRE tactics were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple network-related alerts produced by different detectors on the same host Multiple alerts produced by different detectors were seen on the same host. | Low | Platform Analytics | Palo Alto Networks Platform Alerts, Third-Party Alerts | Execution |
| Analytics | Multiple Rare LOLBIN Process Executions by User A user executed multiple living-off-the-land binary (LOLBIN) processes that are unusual for this user. This may be indicative of a compromised account. | Low | Identity Analytics | XDR Agent | Execution |
| Analytics | Multiple Rare Process Executions in Organization Multiple unusual processes were executed in the organization. This may be indicative of a compromised account. | Informational | Identity Analytics | XDR Agent | Execution |
| Analytics | Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | AzureAD | Initial Access, Credential Access, Execution |
| Analytics | Sudden spike in outbound email volume Unusual amount of emails sent by an internal sender to one or more external recipients within a short timeframe. | Informational | Email Security | Microsoft 365 Emails | Execution, Credential Access |
| Analytics | Suspicious activity indicating a potential abuse of a cloud-native email service A cloud identity performed a sequence of activities which might indicate an intent to abuse the email service to send phishing or spam. | Low | Cortex Cloud | AWS Audit Log, Azure Audit Log | Execution |