Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
118 detectors match the current filters.
Download CSV12 tactics · 60 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
3 detectors
Execution
5 detectors
Persistence
25 detectors
- Account Manipulation (8)
- Valid Accounts (8)
- Boot or Logon Autostart Execution (3)
- Software Extensions (3)
- Create Account (2)
- Hijack Execution Flow (2)
- Scheduled Task/Job (2)
- Account Access Removal (1)
- Event Triggered Execution (1)
- Remote Services (1)
- Server Software Component (1)
- Steal or Forge Authentication Certificates (1)
Privilege Escalation
13 detectors
- Valid Accounts (7)
- Account Manipulation (5)
- Abuse Elevation Control Mechanism (1)
- Access Token Manipulation (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- Hijack Execution Flow (1)
- Steal or Forge Authentication Certificates (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
Defense Evasion
12 detectors
- Indicator Removal (2)
- Virtualization/Sandbox Evasion (2)
- Abuse Elevation Control Mechanism (1)
- Access Token Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Hijack Execution Flow (1)
- Impair Defenses (1)
- Masquerading (1)
- OS Credential Dumping (1)
- Obfuscated Files or Information (1)
- Rogue Domain Controller (1)
Credential Access
34 detectors
- Unsecured Credentials (10)
- Credentials from Password Stores (8)
- OS Credential Dumping (5)
- Steal or Forge Authentication Certificates (5)
- File and Directory Discovery (3)
- Steal or Forge Kerberos Tickets (3)
- Account Discovery (2)
- Valid Accounts (2)
- Account Manipulation (1)
- Adversary-in-the-Middle (1)
- Brute Force (1)
- Forced Authentication (1)
- Modify Authentication Process (1)
- Network Sniffing (1)
- Rogue Domain Controller (1)
- Steal Application Access Token (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
Discovery
28 detectors
- Account Discovery (13)
- File and Directory Discovery (5)
- Permission Groups Discovery (5)
- Remote System Discovery (3)
- System Information Discovery (3)
- System Network Configuration Discovery (3)
- System Owner/User Discovery (3)
- Domain Trust Discovery (2)
- OS Credential Dumping (2)
- Steal or Forge Authentication Certificates (2)
- System Service Discovery (2)
- Virtualization/Sandbox Evasion (2)
- Windows Management Instrumentation (2)
- Browser Information Discovery (1)
- Credentials from Password Stores (1)
- Group Policy Discovery (1)
- Log Enumeration (1)
- Network Sniffing (1)
- Process Discovery (1)
- System Network Connections Discovery (1)
- System Time Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
6 detectors
Collection
13 detectors
Command and Control
1 detector
Exfiltration
5 detectors
Impact
2 detectors