Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
64 detectors match the current filters. tactic: TA0006 ✕
Download CSV8 tactics · 25 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
1 detector
Persistence
1 detector
Privilege Escalation
2 detectors
Defense Evasion
3 detectors
Credential Access
64 detectors
- Unsecured Credentials (19)
- OS Credential Dumping (12)
- Credentials from Password Stores (9)
- Steal or Forge Authentication Certificates (9)
- Steal or Forge Kerberos Tickets (8)
- Account Discovery (4)
- Forced Authentication (4)
- Adversary-in-the-Middle (3)
- Brute Force (3)
- File and Directory Discovery (3)
- Rogue Domain Controller (2)
- Valid Accounts (2)
- Account Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Exploit Public-Facing Application (1)
- Forge Web Credentials (1)
- Input Capture (1)
- Modify Authentication Process (1)
- Network Sniffing (1)
- Steal Application Access Token (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Windows Management Instrumentation (1)
Discovery
7 detectors
- Account Discovery (4)
- File and Directory Discovery (3)
- Steal or Forge Authentication Certificates (3)
- OS Credential Dumping (2)
- Credentials from Password Stores (1)
- Network Sniffing (1)
- Steal or Forge Kerberos Tickets (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Unsecured Credentials (1)
Collection
1 detector