Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

11 detectors match the current filters. technique: T1586 ✕

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics A user rejected an SSO request from an unusual country A user rejected an SSO authentication request from an abnormal country. Low Identity Analytics Okta, OneLogin Credential Access, Resource Development
Analytics Impossible traveler - SSO User connected from several remote countries, at least one of which is not commonly used in the organization, within a short period of time. This may indicate the account is compromised. Low Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics Impossible traveler - VPN A user connected to a VPN service from multiple remote countries in a short period of time, which should normally be impossible. This may indicate the account is compromised. Low Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics IP Rotation Pattern in SSO Spray A high volume of SSO authentication attempts was observed in a short time window. This behavior may indicate a password spray attack targeting multiple accounts. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics Multiple Okta MFA requests sent to a user Multiple SSO MFA attempts were sent to the user. This may indicate an MFA fatigue attack. Informational Identity Analytics Okta Credential Access, Resource Development
Analytics Possible Brute Force in universal authentication An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack. Informational Identity Analytics Credential Access, Resource Development
Analytics Possible Impossible Travel Pattern - SSO A user logged in from several countries in a short period, including at least one location that is rare for the user or organization. This suspicious activity may be a sign of credential theft. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Initial Access, Resource Development
Analytics Possible Password Spray in universal authentication An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack. Informational Identity Analytics Credential Access, Resource Development
Analytics SSO Brute Force An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics SSO Password Spray An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics VPN login Brute-Force attempt A user account failed to log in to a VPN service multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development