Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
215 detectors match the current filters.
Download CSV13 tactics · 53 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
3 detectors
Initial Access
25 detectors
- Valid Accounts (21)
- Steal Application Access Token (5)
- Trusted Relationship (5)
- Unsecured Credentials (5)
- Account Manipulation (2)
- External Remote Services (2)
- Proxy (2)
- Abuse Elevation Control Mechanism (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Forge Web Credentials (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- Remote Services (1)
- Resource Hijacking (1)
- Use Alternate Authentication Material (1)
Execution
28 detectors
- Deploy Container (13)
- Command and Scripting Interpreter (5)
- Escape to Host (5)
- Cloud Administration Command (3)
- Serverless Execution (3)
- User Execution (3)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Remote Services (1)
- Remote System Discovery (1)
- Scheduled Task/Job (1)
- Steal Application Access Token (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Persistence
41 detectors
- Account Manipulation (27)
- Valid Accounts (16)
- Create Account (3)
- Forge Web Credentials (2)
- Remote Services (2)
- Scheduled Task/Job (2)
- Data Destruction (1)
- Exfiltration Over Alternative Protocol (1)
- External Remote Services (1)
- Multi-Factor Authentication Request Generation (1)
- Serverless Execution (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
Privilege Escalation
29 detectors
Defense Evasion
43 detectors
- Impair Defenses (30)
- Modify Cloud Compute Infrastructure (7)
- Data Destruction (2)
- Data from Cloud Storage (2)
- Trusted Relationship (2)
- Valid Accounts (2)
- Abuse Elevation Control Mechanism (1)
- Data Encrypted for Impact (1)
- Data Manipulation (1)
- Indicator Removal (1)
- Masquerading (1)
- Modify Authentication Process (1)
- Transfer Data to Cloud Account (1)
- Unused/Unsupported Cloud Regions (1)
- Weaken Encryption (1)
Credential Access
19 detectors
- Unsecured Credentials (12)
- Valid Accounts (8)
- Steal Application Access Token (5)
- Credentials from Password Stores (4)
- Account Manipulation (2)
- Cloud Service Discovery (2)
- Forge Web Credentials (2)
- Use Alternate Authentication Material (2)
- Command and Scripting Interpreter (1)
- Multi-Factor Authentication Request Generation (1)
- Network Sniffing (1)
- Trusted Relationship (1)
Discovery
16 detectors
- Cloud Infrastructure Discovery (5)
- Cloud Service Discovery (5)
- Account Discovery (3)
- Container and Resource Discovery (2)
- Credentials from Password Stores (2)
- Account Manipulation (1)
- Cloud Administration Command (1)
- Deploy Container (1)
- Network Sniffing (1)
- Password Policy Discovery (1)
- Remote Services (1)
- Remote System Discovery (1)
Lateral Movement
10 detectors
Collection
9 detectors
Command and Control
3 detectors
Exfiltration
26 detectors