Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
75 detectors match the current filters. tactic: TA0002 ✕
Download CSV11 tactics · 27 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
4 detectors
Execution
75 detectors
- Command and Scripting Interpreter (32)
- User Execution (17)
- System Services (10)
- Remote Services (7)
- Scheduled Task/Job (6)
- Container Administration Command (4)
- Windows Management Instrumentation (4)
- Phishing (3)
- Credentials from Password Stores (2)
- Data from Local System (2)
- Deploy Container (2)
- Application Layer Protocol (1)
- Automated Exfiltration (1)
- Boot or Logon Autostart Execution (1)
- Clipboard Data (1)
- Container and Resource Discovery (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Hijack Execution Flow (1)
- Lateral Tool Transfer (1)
- Native API (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- System Binary Proxy Execution (1)
- Valid Accounts (1)
Persistence
6 detectors
Privilege Escalation
6 detectors
Defense Evasion
3 detectors
Credential Access
2 detectors
Discovery
1 detector
Lateral Movement
7 detectors
Collection
3 detectors
Command and Control
1 detector
Exfiltration
2 detectors