Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
88 detectors match the current filters. tactic: TA0005 ✕
Download CSV9 tactics · 32 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
3 detectors
Persistence
10 detectors
Privilege Escalation
8 detectors
Defense Evasion
88 detectors
- System Binary Proxy Execution (21)
- Process Injection (12)
- Masquerading (11)
- Obfuscated Files or Information (9)
- Hijack Execution Flow (7)
- Impair Defenses (7)
- Hide Artifacts (6)
- Application Layer Protocol (3)
- Deobfuscate/Decode Files or Information (3)
- Valid Accounts (3)
- Indicator Removal (2)
- Modify Authentication Process (2)
- Rootkit (2)
- User Execution (2)
- Virtualization/Sandbox Evasion (2)
- Abuse Elevation Control Mechanism (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Create or Modify System Process (1)
- Credentials from Password Stores (1)
- Data Encrypted for Impact (1)
- Exploitation for Defense Evasion (1)
- Indirect Command Execution (1)
- Ingress Tool Transfer (1)
- OS Credential Dumping (1)
- Phishing (1)
- Reflective Code Loading (1)
- Scheduled Task/Job (1)
- Subvert Trust Controls (1)
- Trusted Developer Utilities Proxy Execution (1)
- Unsecured Credentials (1)
- Web Service (1)
Credential Access
4 detectors
Discovery
1 detector
Command and Control
5 detectors
Impact
1 detector