Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
25 detectors match the current filters. tactic: TA0003 ✕
Download CSV8 tactics · 20 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
2 detectors
Persistence
25 detectors
- Hijack Execution Flow (4)
- Scheduled Task/Job (4)
- Boot or Logon Autostart Execution (3)
- Create Account (3)
- Create or Modify System Process (2)
- Event Triggered Execution (2)
- Modify Authentication Process (2)
- Permission Groups Discovery (2)
- Valid Accounts (2)
- Account Discovery (1)
- Account Manipulation (1)
- Application Layer Protocol (1)
- Compromise Host Software Binary (1)
- External Remote Services (1)
- Process Injection (1)
- Server Software Component (1)
- Software Extensions (1)
- Steal or Forge Authentication Certificates (1)
- System Binary Proxy Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
5 detectors
Defense Evasion
7 detectors
Credential Access
3 detectors
Discovery
3 detectors
Command and Control
1 detector