Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

2 detectors match the current filters. technique: T1528 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Possible ConsentFix - OAuth Token Theft Detected Detection of potential OAuth token theft via a forced 'localhost' redirect and first-party app abuse. This indicates an attacker has likely bypassed MFA to hijack a user's cloud session. Informational Identity Threat Detection (ITDR), SaaS Threat Detection AzureAD Initial Access, Credential Access, Execution
Analytics Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access