Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
150 detectors match the current filters.
Download CSV13 tactics · 69 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
1 detector
Initial Access
8 detectors
Execution
29 detectors
- Command and Scripting Interpreter (13)
- Scheduled Task/Job (5)
- User Execution (5)
- Remote Services (4)
- Phishing (3)
- System Services (3)
- Windows Management Instrumentation (2)
- Application Layer Protocol (1)
- Boot or Logon Autostart Execution (1)
- Clipboard Data (1)
- Credentials from Password Stores (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Native API (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
Persistence
15 detectors
Privilege Escalation
11 detectors
Defense Evasion
28 detectors
- System Binary Proxy Execution (10)
- Process Injection (5)
- Impair Defenses (3)
- Application Layer Protocol (2)
- Indicator Removal (2)
- Masquerading (2)
- Obfuscated Files or Information (2)
- Abuse Elevation Control Mechanism (1)
- Command and Scripting Interpreter (1)
- Create or Modify System Process (1)
- Data Encrypted for Impact (1)
- Exploitation for Defense Evasion (1)
- Hide Artifacts (1)
- Hijack Execution Flow (1)
- Phishing (1)
- Rootkit (1)
Credential Access
20 detectors
- Unsecured Credentials (5)
- Steal or Forge Kerberos Tickets (4)
- Adversary-in-the-Middle (2)
- Brute Force (2)
- Credentials from Password Stores (2)
- Steal or Forge Authentication Certificates (2)
- Account Discovery (1)
- Command and Scripting Interpreter (1)
- Exploitation of Remote Services (1)
- Forge Web Credentials (1)
- Input Capture (1)
- Network Sniffing (1)
- OS Credential Dumping (1)
- System Service Discovery (1)
- Use Alternate Authentication Material (1)
Discovery
16 detectors
- System Network Configuration Discovery (5)
- Remote System Discovery (4)
- System Information Discovery (3)
- System Service Discovery (3)
- File and Directory Discovery (2)
- Network Service Discovery (2)
- Account Discovery (1)
- Container and Resource Discovery (1)
- Network Sniffing (1)
- OS Credential Dumping (1)
- Steal or Forge Authentication Certificates (1)
Lateral Movement
19 detectors
Collection
6 detectors
Command and Control
27 detectors
- Application Layer Protocol (16)
- Remote Access Tools (3)
- Exfiltration Over Web Service (2)
- Non-Application Layer Protocol (2)
- Non-Standard Port (2)
- Protocol Tunneling (2)
- Remote Services (2)
- System Binary Proxy Execution (2)
- Web Service (2)
- Command and Scripting Interpreter (1)
- Dynamic Resolution (1)
- Exfiltration Over Alternative Protocol (1)
- Ingress Tool Transfer (1)
Exfiltration
8 detectors