Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
66 detectors match the current filters. tactic: TA0006 ✕
Download CSV10 tactics · 24 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
1 detector
Initial Access
2 detectors
Execution
2 detectors
Persistence
3 detectors
Privilege Escalation
2 detectors
Defense Evasion
4 detectors
Credential Access
66 detectors
- Brute Force (21)
- Unsecured Credentials (13)
- OS Credential Dumping (8)
- Adversary-in-the-Middle (7)
- Steal or Forge Kerberos Tickets (6)
- Credentials from Password Stores (4)
- Use Alternate Authentication Material (4)
- Account Discovery (3)
- Steal or Forge Authentication Certificates (3)
- Valid Accounts (3)
- Command and Scripting Interpreter (2)
- Modify Authentication Process (2)
- Account Manipulation (1)
- Compromise Accounts (1)
- Deobfuscate/Decode Files or Information (1)
- Exploit Public-Facing Application (1)
- Exploitation of Remote Services (1)
- Forced Authentication (1)
- Forge Web Credentials (1)
- Hide Artifacts (1)
- Input Capture (1)
- Network Sniffing (1)
- Remote Services (1)
- System Service Discovery (1)
Discovery
5 detectors
Lateral Movement
6 detectors
Collection
1 detector