Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
131 detectors match the current filters.
Download CSV11 tactics · 66 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
2 detectors
Initial Access
3 detectors
Execution
16 detectors
- System Services (4)
- User Execution (4)
- Windows Management Instrumentation (4)
- Command and Scripting Interpreter (3)
- Create or Modify System Process (3)
- Remote Services (2)
- Account Discovery (1)
- Boot or Logon Autostart Execution (1)
- Masquerading (1)
- Native API (1)
- Phishing (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Unsecured Credentials (1)
Persistence
31 detectors
- Boot or Logon Autostart Execution (8)
- Scheduled Task/Job (5)
- Server Software Component (5)
- Create or Modify System Process (3)
- Event Triggered Execution (3)
- Software Extensions (3)
- External Remote Services (2)
- Remote Services (2)
- System Services (2)
- Account Manipulation (1)
- Boot or Logon Initialization Scripts (1)
- Hijack Execution Flow (1)
- Masquerading (1)
- Pre-OS Boot (1)
- User Execution (1)
Privilege Escalation
12 detectors
Defense Evasion
20 detectors
- Impair Defenses (4)
- Masquerading (3)
- Process Injection (3)
- Abuse Elevation Control Mechanism (2)
- Virtualization/Sandbox Evasion (2)
- Create or Modify System Process (1)
- Deobfuscate/Decode Files or Information (1)
- Hide Artifacts (1)
- Indicator Removal (1)
- Modify Registry (1)
- OS Credential Dumping (1)
- Obfuscated Files or Information (1)
- Proxy (1)
- Reflective Code Loading (1)
- Rogue Domain Controller (1)
- System Binary Proxy Execution (1)
- User Execution (1)
Credential Access
33 detectors
- Unsecured Credentials (14)
- OS Credential Dumping (11)
- Credentials from Password Stores (6)
- Account Discovery (2)
- Adversary-in-the-Middle (1)
- File and Directory Discovery (1)
- Forced Authentication (1)
- Input Capture (1)
- Network Sniffing (1)
- Rogue Domain Controller (1)
- Steal Web Session Cookie (1)
- Steal or Forge Authentication Certificates (1)
- Steal or Forge Kerberos Tickets (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Windows Management Instrumentation (1)
Discovery
22 detectors
- Account Discovery (10)
- File and Directory Discovery (3)
- Remote System Discovery (3)
- System Information Discovery (3)
- System Owner/User Discovery (3)
- Browser Information Discovery (2)
- OS Credential Dumping (2)
- Permission Groups Discovery (2)
- System Service Discovery (2)
- Virtualization/Sandbox Evasion (2)
- Windows Management Instrumentation (2)
- Automated Collection (1)
- Credentials from Password Stores (1)
- Data from Local System (1)
- Network Sniffing (1)
- Process Discovery (1)
- System Network Configuration Discovery (1)
- System Network Connections Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
11 detectors
Collection
10 detectors
Command and Control
4 detectors