Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

47 detectors match the current filters. technique: T1552 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics BIOC A Command Line Interface (CLI) command was executed from a GCP serverless compute service A GCP serverless compute service token was used to execute a Command Line Interface (CLI) command. Low Cortex Cloud Gcp Audit Log Initial Access, Credential Access
Analytics BIOC A Command Line Interface (CLI) command was executed from an AWS serverless compute service AWS serverless compute service token was used to execute a Command Line Interface (CLI) command. This may indicate token theft due to the nature of serverless compute. Low Cortex Cloud AWS Audit Log Initial Access, Credential Access, Execution
Analytics BIOC A compute-attached identity executed API calls outside the instance's region A compute-attached identity performed actions outside the compute instance region. Informational Cortex Cloud AWS Audit Log Initial Access, Credential Access
Analytics BIOC A Kubernetes secret was created or deleted A Kubernetes secret was created or deleted. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics BIOC A suspicious process enrolled for a certificate A suspicious process enrolled for a certificate. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC A user created a pfx file for the first time A user created a pfx file for the first time. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to kubelet credentials file A process accessed a kubelet credentials file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes CA certificate file A process accessed a Kubernetes CA certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Access to Kubernetes configuration file A process accessed a Kubernetes node configuration file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC An Azure Key Vault was modified Azure Key Vault has been modified or deleted by an Identity. This could be an indication of unauthorized access or malicious activity. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC An identity accessed Azure Kubernetes Secrets An identity has accessed or attempted to access Azure Kubernetes secrets or Config Objects. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Key Vault modification Azure Key Vault modifications can be crucial as it stores secrets e.g. encryption keys, certifications, etc. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Azure Key Vault Secrets were modified Azure key vault secrets were modified. A change or deletion of secrets in Azure Key Vault has been detected. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Copy a user's GnuPG directory with rsync Copy a user's GnuPG (.gnupg) directory on to a staging folder using the 'find' and 'rsync' commands. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Extracting credentials from Unix files Suspicious Unix files containing insecurely stored credentials were accessed. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Granting Access to an Account Azure access has been granted to an account. Informational Cortex Cloud Azure Audit Log Initial Access, Credential Access
Analytics BIOC Kubernetes admission controller activity A Kubernetes admission controller has been created or modified. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Persistence, Credential Access
Analytics BIOC Kubernetes secret enumeration activity Kubectl secret enumeration command was executed. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Kubernetes secrets enumeration for the first time An identity listed Kubernetes secrets for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics BIOC Possible Search For Password Files Attackers often search for files that have passwords in them. Medium Platform Analytics XDR Agent Credential Access
Analytics BIOC Potential SCCM credential harvesting using WMI detected Attackers or malware may use WMI queries to obtain domain credentials that are used by the SCCM. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Execution, Credential Access
Analytics BIOC PowerShell pfx certificate extraction PowerShell was used to extract a pfx certificate file. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Reading bash command history file Attackers may access the bash history file to glean cleartext usernames and passwords that were entered on the command line. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Remote usage of an App engine Service Account token A GCP Service Account token, which is attached to an app engine, was used externally of the cloud environment. Informational Cortex Cloud Gcp Audit Log Credential Access
Analytics BIOC Remote usage of an AWS service token An AWS service token was used externally of the cloud environment. Low Cortex Cloud AWS Audit Log Credential Access, Lateral Movement, Initial Access
Analytics BIOC Remote usage of an Azure Managed Identity token An Azure Managed Identity token, which is attached to a compute service, was used externally of the cloud environment. Low Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Remote usage of an Azure Service Principal token An Azure Service Principal token was used externally of the cloud environment. Informational Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Remote usage of AWS Lambda's role An AWS Lambda's role was used externally of the cloud environment. Informational Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics BIOC Remote usage of VM Service Account token A GCP Service Account token, which is attached to a VM, was used externally of the cloud environment. Informational Cortex Cloud Gcp Audit Log Credential Access
Analytics BIOC Retrieval of kubelet credentials A process retrieved kubelet credentials. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Suspicious Kubernetes pod token access A Kubernetes pod has accessed the access token of another pod. This could indicate potential unauthorized access or a security breach within the cluster. Medium Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious process accessed certificate files A suspicious process accessed certificate files. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Suspicious usage of EC2 token An AWS EC2 STS token was used externally from an EC2 instance. Low Cortex Cloud AWS Audit Log Credential Access, Initial Access
Analytics BIOC Uncommon access to Microsoft Teams credential files Sensitive Microsoft Teams credential files were accessed. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Uncommon attempt at grabbing credentials from a sensitive file A process made an uncommon attempt to access a file that may contain sensitive information. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access, Discovery
Analytics BIOC Uncommon Azure Cosmos DB master key read by identity A cloud identity read master keys from an Azure Cosmos DB account, which is uncommon for this identity. Low Cortex Cloud Azure Audit Log Credential Access
Analytics BIOC Uncommon SQL like command line Uncommon SQL query in command line of an executed process. Informational Platform Analytics XDR Agent Credential Access
Analytics BIOC Unprivileged process opened a registry hive An unprivileged process opened a registry hive directly. Low Platform Analytics XDR Agent Credential Access
Analytics BIOC Unusual ADConnect database file access An unusual process accessed the ADConnect database files. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual certificate management activity A cloud identity performed a certificate management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual CIM repository file access An uncommon process accessed the CIM repository file, potentially to retrieve stored NNA credentials for unauthorized use. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual cloud Instance Metadata Service (IMDS) access A request to cloud Instance Metadata Service (IMDS) was made by an unusual process. This process does not usually access the Instance Metadata Service. An attacker may extract cloud compute tokens to gain access to a cloud environment. Informational Cortex Cloud XDR Agent Credential Access
Analytics BIOC Unusual key management activity A cloud identity performed a key management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access
Analytics BIOC Unusual Kubernetes secret access Suspicious Kubernetes secret access. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs Credential Access
Analytics BIOC Unusual Kubernetes service account file read An unusual process opened a Kubernetes service account file for the first time. Informational Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual process accessed FTP Client credentials An unusual process has accessed a third-party FTP client's credential file. Low Platform Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unusual secret management activity A cloud Identity performed a secret management operation for the first time. Informational Cortex Cloud AWS Audit Log, Azure Audit Log, Gcp Audit Log Credential Access