Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
9 detectors match the current filters. technique: T1530 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | An EBS snapshot block was downloaded An EBS snapshot block was downloaded using the EBS direct API. This may indicate an attacker's attempt to exfiltrate data from a volume snapshot in the cloud environment. | Informational | Cortex Cloud | AWS Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a backup cloud storage An identity accessed a backup cloud storage. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An identity accessed a cloud storage for the first time An identity accessed a cloud storage resource for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | An unusual read activity of cloud object An identity accessed a cloud object filetype for the first time. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection, Exfiltration |
| Analytics BIOC | Cloud compute volume creation attempt An attempt was made to create an EBS volume. | Informational | Cortex Cloud | AWS Audit Log | Defense Evasion, Collection |
| Analytics BIOC | Cloud snapshot created or modified A cloud identity has created or modified a cloud snapshot. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Exfiltration, Defense Evasion, Collection |
| Analytics BIOC | EBS snapshots were created from an EC2 instance One or more EBS snapshots were created from an EC2 instance. | Informational | Cortex Cloud | AWS Audit Log | Collection |
| Analytics BIOC | Suspicious ML Model Download A model artifact was accessed from cloud storage by an identity that typically doesn't interact with model files. MITRE ATLAS Technique: AML.T0035 - ML Artifact Collection. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log | Collection |
| Analytics BIOC | User accessed SaaS resource via anonymous link A user accessed a SaaS resource via an anonymous link. | Informational | Identity Threat Detection (ITDR), SaaS Threat Detection | Google Workspace Audit Logs, Office 365 Audit | Collection |