Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
431 detectors match the current filters.
Download CSV14 tactics · 105 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
5 detectors
Resource Development
2 detectors
Initial Access
31 detectors
- Phishing (12)
- Valid Accounts (10)
- Exploit Public-Facing Application (5)
- External Remote Services (4)
- Exfiltration Over Alternative Protocol (3)
- User Execution (3)
- Application Layer Protocol (2)
- Non-Standard Port (2)
- Server Software Component (2)
- Trusted Relationship (2)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Data from Information Repositories (1)
- Exploitation of Remote Services (1)
- Process Injection (1)
- Proxy (1)
- Unsecured Credentials (1)
Execution
75 detectors
- Command and Scripting Interpreter (32)
- User Execution (17)
- System Services (10)
- Remote Services (7)
- Scheduled Task/Job (6)
- Container Administration Command (4)
- Windows Management Instrumentation (4)
- Phishing (3)
- Credentials from Password Stores (2)
- Data from Local System (2)
- Deploy Container (2)
- Application Layer Protocol (1)
- Automated Exfiltration (1)
- Boot or Logon Autostart Execution (1)
- Clipboard Data (1)
- Container and Resource Discovery (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Hijack Execution Flow (1)
- Lateral Tool Transfer (1)
- Native API (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- System Binary Proxy Execution (1)
- Valid Accounts (1)
Persistence
52 detectors
- Boot or Logon Autostart Execution (12)
- Scheduled Task/Job (9)
- Hijack Execution Flow (7)
- Create or Modify System Process (5)
- Account Manipulation (4)
- Event Triggered Execution (4)
- Create Account (3)
- Valid Accounts (3)
- External Remote Services (2)
- Modify Authentication Process (2)
- Permission Groups Discovery (2)
- Process Injection (2)
- Server Software Component (2)
- Account Discovery (1)
- Application Layer Protocol (1)
- BITS Jobs (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Escape to Host (1)
- Masquerading (1)
- Replication Through Removable Media (1)
- Software Extensions (1)
- Steal or Forge Authentication Certificates (1)
- System Binary Proxy Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
33 detectors
- Abuse Elevation Control Mechanism (6)
- Escape to Host (6)
- Hijack Execution Flow (6)
- Valid Accounts (6)
- Scheduled Task/Job (3)
- Account Manipulation (2)
- Create or Modify System Process (2)
- Exploitation for Privilege Escalation (2)
- Access Token Manipulation (1)
- Boot or Logon Autostart Execution (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Process Injection (1)
- Steal or Forge Authentication Certificates (1)
- System Services (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
- User Execution (1)
Defense Evasion
88 detectors
- System Binary Proxy Execution (21)
- Process Injection (12)
- Masquerading (11)
- Obfuscated Files or Information (9)
- Hijack Execution Flow (7)
- Impair Defenses (7)
- Hide Artifacts (6)
- Application Layer Protocol (3)
- Deobfuscate/Decode Files or Information (3)
- Valid Accounts (3)
- Indicator Removal (2)
- Modify Authentication Process (2)
- Rootkit (2)
- User Execution (2)
- Virtualization/Sandbox Evasion (2)
- Abuse Elevation Control Mechanism (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Create or Modify System Process (1)
- Credentials from Password Stores (1)
- Data Encrypted for Impact (1)
- Exploitation for Defense Evasion (1)
- Indirect Command Execution (1)
- Ingress Tool Transfer (1)
- OS Credential Dumping (1)
- Phishing (1)
- Reflective Code Loading (1)
- Scheduled Task/Job (1)
- Subvert Trust Controls (1)
- Trusted Developer Utilities Proxy Execution (1)
- Unsecured Credentials (1)
- Web Service (1)
Credential Access
66 detectors
- Brute Force (21)
- Unsecured Credentials (13)
- OS Credential Dumping (8)
- Adversary-in-the-Middle (7)
- Steal or Forge Kerberos Tickets (6)
- Credentials from Password Stores (4)
- Use Alternate Authentication Material (4)
- Account Discovery (3)
- Steal or Forge Authentication Certificates (3)
- Valid Accounts (3)
- Command and Scripting Interpreter (2)
- Modify Authentication Process (2)
- Account Manipulation (1)
- Compromise Accounts (1)
- Deobfuscate/Decode Files or Information (1)
- Exploit Public-Facing Application (1)
- Exploitation of Remote Services (1)
- Forced Authentication (1)
- Forge Web Credentials (1)
- Hide Artifacts (1)
- Input Capture (1)
- Network Sniffing (1)
- Remote Services (1)
- System Service Discovery (1)
Discovery
42 detectors
- Remote System Discovery (8)
- System Network Configuration Discovery (8)
- Account Discovery (7)
- Container and Resource Discovery (7)
- Network Service Discovery (6)
- System Information Discovery (6)
- System Service Discovery (6)
- Create Account (3)
- Permission Groups Discovery (3)
- Brute Force (2)
- File and Directory Discovery (2)
- Cloud Service Discovery (1)
- Deploy Container (1)
- Escape to Host (1)
- Network Share Discovery (1)
- Network Sniffing (1)
- OS Credential Dumping (1)
- Process Discovery (1)
- Remote Services (1)
- Resource Hijacking (1)
- Steal or Forge Authentication Certificates (1)
- System Owner/User Discovery (1)
- Virtualization/Sandbox Evasion (1)
Lateral Movement
48 detectors
- Remote Services (29)
- Use Alternate Authentication Material (14)
- Adversary-in-the-Middle (4)
- System Services (4)
- Exploitation of Remote Services (3)
- Command and Scripting Interpreter (2)
- Remote Access Tools (2)
- Brute Force (1)
- Exploit Public-Facing Application (1)
- Forge Web Credentials (1)
- Hijack Execution Flow (1)
- Lateral Tool Transfer (1)
- Network Service Discovery (1)
- Remote Service Session Hijacking (1)
- Replication Through Removable Media (1)
- Valid Accounts (1)
- Windows Management Instrumentation (1)
Collection
10 detectors
Command and Control
59 detectors
- Application Layer Protocol (34)
- Non-Standard Port (6)
- Web Service (5)
- Exfiltration Over Web Service (4)
- Non-Application Layer Protocol (4)
- Proxy (4)
- Remote Access Tools (4)
- System Binary Proxy Execution (4)
- Ingress Tool Transfer (3)
- Protocol Tunneling (3)
- Dynamic Resolution (2)
- Exfiltration Over Alternative Protocol (2)
- Exfiltration Over C2 Channel (2)
- Phishing (2)
- Remote Services (2)
- Trusted Relationship (2)
- Command and Scripting Interpreter (1)
- Masquerading (1)
- Software Extensions (1)
- Valid Accounts (1)
Exfiltration
24 detectors
Impact
11 detectors