Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters. technique: T1613 ✕
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Analytics BIOC | A Kubernetes service account has enumerated its permissions A Kubernetes service account has enumerated its permissions using the self subject review API. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics BIOC | Kubelet server communication from a pod The Kubelet server was accessed from within a pod, which may indicate an attempt to escape container boundaries or escalate privileges. | Informational | Platform Analytics | XDR Agent | Privilege Escalation, Discovery |
| Analytics BIOC | Kubernetes API server communication from within a pod The Kubernetes API server was accessed from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics | Kubernetes enumeration activity An identity attempted to discover available resources within a cluster. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Discovery |
| Analytics | Kubernetes environment enumeration activity Multiple resources within a Kubernetes cluster were enumerated. This may indicate an adversary attempting to map the Kubernetes environment and discover resources that may assist to perform additional attacks within the environment. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes version disclosure The Kubernetes API server was inquired about the Kubernetes version by a process from within a pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Kubernetes vulnerability scanner activity A Kubernetes cluster was scanned by a known vulnerability scanner. | Medium | Platform Analytics | XDR Agent | Execution, Discovery |
| Analytics BIOC | Kubernetes vulnerability scanning tool usage A known vulnerability scanning tool was used within a Kubernetes cluster. | Medium | Cortex Cloud | AWS Audit Log, Azure Audit Log, Gcp Audit Log, Kubernetes Audit Logs | Execution, Discovery |
| Analytics | Suspicious container reconnaissance activity in a Kubernetes pod A process performed multiple consecutive container discovery commands from within a Kubernetes Pod. | Informational | Platform Analytics | XDR Agent | Discovery |
| Analytics BIOC | Unusual Kubernetes dashboard communication from a pod The Kubernetes dashboard was accessed by an unusual pod within the environment. | Low | Platform Analytics | XDR Agent | Discovery |