Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
76 detectors match the current filters.
Download CSV9 tactics · 34 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
1 detector
Initial Access
3 detectors
Persistence
26 detectors
Privilege Escalation
21 detectors
Defense Evasion
10 detectors
- Hide Artifacts (2)
- Impair Defenses (2)
- Valid Accounts (2)
- Access Token Manipulation (1)
- Create Account (1)
- Credentials from Password Stores (1)
- Deobfuscate/Decode Files or Information (1)
- Hijack Execution Flow (1)
- Indicator Removal (1)
- Masquerading (1)
- OS Credential Dumping (1)
- Rogue Domain Controller (1)
- Unsecured Credentials (1)
Credential Access
27 detectors
- Steal or Forge Authentication Certificates (8)
- Steal or Forge Kerberos Tickets (7)
- Brute Force (3)
- Forced Authentication (3)
- Unsecured Credentials (3)
- Account Discovery (2)
- Adversary-in-the-Middle (2)
- Credentials from Password Stores (2)
- File and Directory Discovery (2)
- Valid Accounts (2)
- Account Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Modify Authentication Process (1)
- OS Credential Dumping (1)
- Rogue Domain Controller (1)
- Steal Application Access Token (1)
Discovery
12 detectors
- Account Discovery (7)
- Permission Groups Discovery (3)
- Steal or Forge Authentication Certificates (3)
- Domain Trust Discovery (2)
- File and Directory Discovery (2)
- Remote System Discovery (2)
- System Network Configuration Discovery (2)
- Group Policy Discovery (1)
- Log Enumeration (1)
- Steal or Forge Kerberos Tickets (1)
Lateral Movement
2 detectors
Impact
2 detectors