Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
29 detectors match the current filters. tactic: TA0005 ✕
Download CSV8 tactics · 19 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
1 detector
Persistence
2 detectors
Privilege Escalation
2 detectors
Defense Evasion
29 detectors
- System Binary Proxy Execution (10)
- Process Injection (5)
- Impair Defenses (3)
- Application Layer Protocol (2)
- Indicator Removal (2)
- Masquerading (2)
- Obfuscated Files or Information (2)
- Abuse Elevation Control Mechanism (1)
- Command and Scripting Interpreter (1)
- Create or Modify System Process (1)
- Credentials from Password Stores (1)
- Data Encrypted for Impact (1)
- Deobfuscate/Decode Files or Information (1)
- Exploitation for Defense Evasion (1)
- Hide Artifacts (1)
- Hijack Execution Flow (1)
- Phishing (1)
- Rootkit (1)
- Unsecured Credentials (1)
Credential Access
1 detector
Command and Control
2 detectors
Impact
1 detector