Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
84 detectors match the current filters.
Download CSV13 tactics · 54 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
3 detectors
Initial Access
4 detectors
Execution
8 detectors
Persistence
25 detectors
- Account Manipulation (6)
- Valid Accounts (6)
- Boot or Logon Autostart Execution (4)
- Create or Modify System Process (3)
- Scheduled Task/Job (3)
- Server Software Component (3)
- Event Triggered Execution (2)
- External Remote Services (2)
- Masquerading (2)
- System Services (2)
- Boot or Logon Initialization Scripts (1)
- Create Account (1)
- Hide Artifacts (1)
- Pre-OS Boot (1)
- Remote Services (1)
- User Execution (1)
Privilege Escalation
13 detectors
Defense Evasion
15 detectors
- Impair Defenses (5)
- Hide Artifacts (2)
- Masquerading (2)
- Process Injection (2)
- Valid Accounts (2)
- Abuse Elevation Control Mechanism (1)
- Create or Modify System Process (1)
- Credentials from Password Stores (1)
- Deobfuscate/Decode Files or Information (1)
- Modify Registry (1)
- OS Credential Dumping (1)
- Proxy (1)
- Reflective Code Loading (1)
- Rogue Domain Controller (1)
- System Binary Proxy Execution (1)
- Unsecured Credentials (1)
Credential Access
23 detectors
- Unsecured Credentials (7)
- OS Credential Dumping (6)
- Steal or Forge Authentication Certificates (4)
- Steal or Forge Kerberos Tickets (3)
- Account Discovery (2)
- Brute Force (2)
- Forced Authentication (2)
- Adversary-in-the-Middle (1)
- Credentials from Password Stores (1)
- Deobfuscate/Decode Files or Information (1)
- Forge Web Credentials (1)
- Rogue Domain Controller (1)
- Windows Management Instrumentation (1)
Discovery
5 detectors
Lateral Movement
6 detectors
Collection
8 detectors
- Data Staged (3)
- Data from Local System (3)
- Archive Collected Data (1)
- Audio Capture (1)
- Automated Collection (1)
- Automated Exfiltration (1)
- Browser Information Discovery (1)
- Data from Cloud Storage (1)
- Email Collection (1)
- Exfiltration Over Physical Medium (1)
- Gather Victim Host Information (1)
- Video Capture (1)
Command and Control
3 detectors
Exfiltration
2 detectors
Impact
1 detector