Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
80 detectors match the current filters.
Download CSV12 tactics · 42 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
4 detectors
Initial Access
6 detectors
Execution
2 detectors
Persistence
3 detectors
Privilege Escalation
4 detectors
Defense Evasion
2 detectors
Credential Access
31 detectors
- Brute Force (18)
- Adversary-in-the-Middle (5)
- Use Alternate Authentication Material (4)
- Steal or Forge Kerberos Tickets (3)
- Unsecured Credentials (3)
- Valid Accounts (3)
- Account Discovery (2)
- Account Manipulation (1)
- Credentials from Password Stores (1)
- Deobfuscate/Decode Files or Information (1)
- Exploit Public-Facing Application (1)
- OS Credential Dumping (1)
- Remote Services (1)
- Steal or Forge Authentication Certificates (1)
Discovery
14 detectors
Lateral Movement
12 detectors
Command and Control
11 detectors
Exfiltration
8 detectors