Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
39 detectors match the current filters. tactic: TA0005 ✕
Download CSV10 tactics · 22 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
2 detectors
Execution
2 detectors
Persistence
3 detectors
Privilege Escalation
2 detectors
Defense Evasion
39 detectors
- Impair Defenses (22)
- Modify Cloud Compute Infrastructure (6)
- Account Manipulation (2)
- Command and Scripting Interpreter (2)
- Indicator Removal (2)
- Unused/Unsupported Cloud Regions (2)
- Valid Accounts (2)
- Cloud Administration Command (1)
- Cloud Infrastructure Discovery (1)
- Cloud Service Discovery (1)
- Data Destruction (1)
- Data from Cloud Storage (1)
- Domain or Tenant Policy Modification (1)
- Email Collection (1)
- File and Directory Permissions Modification (1)
- Hide Artifacts (1)
- Masquerading (1)
- Network Boundary Bridging (1)
- Remote Services (1)
- Service Stop (1)
- Transfer Data to Cloud Account (1)
- Use Alternate Authentication Material (1)
Discovery
1 detector
Lateral Movement
1 detector
Collection
2 detectors
Exfiltration
1 detector
Impact
2 detectors