Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
31 detectors match the current filters. tactic: TA0005 ✕
Download CSV7 tactics · 23 techniques · cell shade = number of matching detectors; click a cell to list them.
Execution
1 detector
Persistence
4 detectors
Privilege Escalation
3 detectors
Defense Evasion
31 detectors
- Impair Defenses (7)
- Masquerading (4)
- Hide Artifacts (3)
- Process Injection (3)
- Abuse Elevation Control Mechanism (2)
- Deobfuscate/Decode Files or Information (2)
- Indicator Removal (2)
- OS Credential Dumping (2)
- Rogue Domain Controller (2)
- Valid Accounts (2)
- Virtualization/Sandbox Evasion (2)
- Access Token Manipulation (1)
- Create Account (1)
- Create or Modify System Process (1)
- Credentials from Password Stores (1)
- Hijack Execution Flow (1)
- Modify Registry (1)
- Obfuscated Files or Information (1)
- Proxy (1)
- Reflective Code Loading (1)
- System Binary Proxy Execution (1)
- Unsecured Credentials (1)
- User Execution (1)
Credential Access
3 detectors
Discovery
2 detectors
Command and Control
1 detector