Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
10 detectors match the current filters.
Download CSV| Type | Name | Severity | Module | Data source / event | ATT&CK |
|---|---|---|---|---|---|
| Correlation Rule | Alibaba ActionTrail - multiple unauthorized action attempts detected by a user This alert will trigger in an event where multiple attempts of unauthorized actions were detected in the Alibaba ActionTrail account | Medium | Platform Analytics | alibaba_action_trail_raw | |
| Correlation Rule | Chrome - Chrome Extension Install Event The extension $xdm.target.resource.name was installed on $xdm.source.host.hostname by $xdm.intermediate.user.username | Low | Platform Analytics | google_workspace_chrome_raw | Persistence |
| Correlation Rule | Chrome - Known Malicious Site Visit Unsafe site $xdm.network.http.url was visited by $xdm.source.user.username via chrome profile $xdm.intermediate.user.username. | Medium | Platform Analytics | google_workspace_chrome_raw | |
| Correlation Rule | Chrome - Known Malware Downloaded User $xdm.source.user.username downloaded the file $xdm.target.file.filename via chrome profile $$xdm.intermediate.user.username on $xdm.source.host.hostname. | Medium | Platform Analytics | google_workspace_chrome_raw | Execution |
| Correlation Rule | Chrome - User Phished and/or Password Re-use/Breach event The user $xdm.source.user.username had $xdm.event.type event via $xdm.intermediate.user.username chrome profile, which resulted in $xdm.observer.action. | Medium | Platform Analytics | google_workspace_chrome_raw | Initial Access |
| Correlation Rule | CyberArk Failed Logins This correlation rule will trigger in an event in which 4 or more Failed Logins events occurred from a single user during a 10 minutes timeframe. | Medium | Platform Analytics | cyberark_identity_raw | |
| Correlation Rule | DropBox - Massive File Alterations This rule detects more than 100 edited files during an hour by the same user. This is a suspicious behavior which can be an indication of a ransomware attack. | High | Platform Analytics | dropbox_dropbox_raw | Impact |
| Correlation Rule | DropBox - Massive File Downloads This rule detects more than 100 downloaded files during an hour by the same user. This is a suspicious behavior which can be an indication of a data exfiltration. | Medium | Platform Analytics | dropbox_dropbox_raw | Exfiltration |
| Correlation Rule | Gitlab - User Permission Changed User''s permissions have changed from Guest to Owner | Medium | Platform Analytics | gitlab_gitlab_raw | |
| Correlation Rule | Microsoft Defender for Endpoint - Malware Detected This alert will trigger when Malware is detected by Microsoft Defender for Endpoint. | High | Enterprise Runtime Security, Cortex Cloud | Microsoft Defender Advanced Threat Protection, microsoft_365_defender_raw |