Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

10 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Correlation Rule Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account Medium Platform Analytics alibaba_action_trail_raw
Correlation Rule Chrome - Chrome Extension Install Event The extension $xdm.target.resource.name was installed on $xdm.source.host.hostname by $xdm.intermediate.user.username Low Platform Analytics google_workspace_chrome_raw Persistence
Correlation Rule Chrome - Known Malicious Site Visit Unsafe site $xdm.network.http.url was visited by $xdm.source.user.username via chrome profile $xdm.intermediate.user.username. Medium Platform Analytics google_workspace_chrome_raw
Correlation Rule Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. Medium Platform Analytics google_workspace_chrome_raw Execution
Correlation Rule Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. Medium Platform Analytics google_workspace_chrome_raw Initial Access
Correlation Rule CyberArk Failed Logins This correlation rule will trigger in an event in which 4 or more Failed Logins events occurred from a single user during a 10 minutes timeframe. Medium Platform Analytics cyberark_identity_raw
Correlation Rule DropBox - Massive File Alterations This rule detects more than 100 edited files during an hour by the same user. This is a suspicious behavior which can be an indication of a ransomware attack. High Platform Analytics dropbox_dropbox_raw Impact
Correlation Rule DropBox - Massive File Downloads This rule detects more than 100 downloaded files during an hour by the same user. This is a suspicious behavior which can be an indication of a data exfiltration. Medium Platform Analytics dropbox_dropbox_raw Exfiltration
Correlation Rule Gitlab - User Permission Changed User''s permissions have changed from Guest to Owner Medium Platform Analytics gitlab_gitlab_raw
Correlation Rule Microsoft Defender for Endpoint - Malware Detected This alert will trigger when Malware is detected by Microsoft Defender for Endpoint. High Enterprise Runtime Security, Cortex Cloud Microsoft Defender Advanced Threat Protection, microsoft_365_defender_raw