Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
155 detectors match the current filters.
Download CSV13 tactics · 54 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
2 detectors
Initial Access
15 detectors
Execution
20 detectors
Persistence
25 detectors
- Account Manipulation (14)
- Valid Accounts (12)
- External Remote Services (2)
- Cloud Administration Command (1)
- Command and Scripting Interpreter (1)
- Create Account (1)
- Data Destruction (1)
- Impair Defenses (1)
- Modify Authentication Process (1)
- Remote Services (1)
- Scheduled Task/Job (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
Privilege Escalation
20 detectors
Defense Evasion
38 detectors
- Impair Defenses (22)
- Modify Cloud Compute Infrastructure (6)
- Account Manipulation (2)
- Command and Scripting Interpreter (2)
- Indicator Removal (2)
- Valid Accounts (2)
- Cloud Administration Command (1)
- Data Destruction (1)
- Data from Cloud Storage (1)
- Domain or Tenant Policy Modification (1)
- Email Collection (1)
- File and Directory Permissions Modification (1)
- Hide Artifacts (1)
- Masquerading (1)
- Network Boundary Bridging (1)
- Remote Services (1)
- Service Stop (1)
- Transfer Data to Cloud Account (1)
- Unused/Unsupported Cloud Regions (1)
- Use Alternate Authentication Material (1)
Credential Access
18 detectors
Discovery
7 detectors
Lateral Movement
5 detectors
Collection
8 detectors
Command and Control
3 detectors
Exfiltration
9 detectors