Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
11 detectors match the current filters. technique: T1213 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Google Workspace identity used the security investigation tool A Google Workspace identity used the security investigation tool The Google Workspace security investigation tool can be abused to access sensitive data. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs | Collection |
| Analytics BIOC | A rare FTP user has been detected on an existing FTP server A rare or new FTP user has been detected on an existing FTP server. | Low | Platform Analytics | Palo Alto Networks Firewall EAL Logs | Initial Access, Collection |
| Analytics BIOC | DLP sensitive data exposed to external users A user triggered an O365 DLP rule match on data that is viewable by external users. This may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Microsoft Teams messages were exported from conversation Microsoft Teams messages were exported from conversation. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics BIOC | New FTP Server A new FTP server has been detected. | Low | Platform Analytics | Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls | Initial Access, Collection |
| Analytics BIOC | OneDrive file download A file was downloaded from OneDrive using the Microsoft Graph API. | Informational | Cortex Cloud | Azure Audit Log, Microsoft Graph Logs | Collection |
| Analytics BIOC | Rare DLP rule match by user A user triggered an O365 DLP rule match, which may indicate an attacker's attempt to access sensitive information. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection, Email Security | Office 365 Audit | Collection |
| Analytics BIOC | Unusual process accessed a macOS notes DB file An unusual process has accessed a user's notes DB file. | Informational | Platform Analytics | XDR Agent with eXtended Threat Hunting (XTH) | Collection |
| Analytics | User accessed multiple O365 AIP sensitive files A user accessed multiple O365 AIP sensitive files. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| Analytics | User exported multiple messages in Microsoft Teams via Graph API A user exported multiple messages in Microsoft Teams via Graph API. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Office 365 Audit | Collection |
| BIOC | Windows hosts file written to Check for hosts file redirection, overriding the system's default hosts file to manipulate DNS. | Informational | Platform Analytics | File | Collection |