Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
33 detectors match the current filters. tactic: TA0004 ✕
Download CSV7 tactics · 18 techniques · cell shade = number of matching detectors; click a cell to list them.
Execution
6 detectors
Persistence
12 detectors
Privilege Escalation
33 detectors
- Abuse Elevation Control Mechanism (6)
- Escape to Host (6)
- Hijack Execution Flow (6)
- Valid Accounts (6)
- Scheduled Task/Job (3)
- Account Manipulation (2)
- Create or Modify System Process (2)
- Exploitation for Privilege Escalation (2)
- Access Token Manipulation (1)
- Boot or Logon Autostart Execution (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Process Injection (1)
- Steal or Forge Authentication Certificates (1)
- System Services (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
- User Execution (1)
Defense Evasion
8 detectors
Credential Access
2 detectors
Discovery
1 detector
Lateral Movement
1 detector