Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
397 detectors match the current filters.
Download CSV13 tactics · 72 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
5 detectors
Initial Access
38 detectors
- Valid Accounts (31)
- Unsecured Credentials (9)
- Trusted Relationship (8)
- Steal Application Access Token (6)
- Resource Hijacking (3)
- Abuse Elevation Control Mechanism (2)
- Account Manipulation (2)
- Exploit Public-Facing Application (2)
- External Remote Services (2)
- Forge Web Credentials (2)
- Modify Authentication Process (2)
- Proxy (2)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Remote Services (1)
- Use Alternate Authentication Material (1)
Execution
37 detectors
- Deploy Container (13)
- Command and Scripting Interpreter (10)
- Cloud Administration Command (7)
- Escape to Host (5)
- User Execution (5)
- Remote Services (3)
- Serverless Execution (3)
- Impair Defenses (2)
- Account Manipulation (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Remote System Discovery (1)
- Scheduled Task/Job (1)
- Steal Application Access Token (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Persistence
70 detectors
- Account Manipulation (50)
- Valid Accounts (22)
- Create Account (5)
- External Remote Services (3)
- Forge Web Credentials (2)
- Remote Services (2)
- Scheduled Task/Job (2)
- Cloud Administration Command (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Exfiltration Over Alternative Protocol (1)
- Impair Defenses (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- Serverless Execution (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
- Use Alternate Authentication Material (1)
Privilege Escalation
50 detectors
Defense Evasion
80 detectors
- Impair Defenses (56)
- Modify Cloud Compute Infrastructure (10)
- Data Destruction (3)
- Indicator Removal (3)
- Valid Accounts (3)
- Command and Scripting Interpreter (2)
- Data from Cloud Storage (2)
- Domain or Tenant Policy Modification (2)
- File and Directory Permissions Modification (2)
- Transfer Data to Cloud Account (2)
- Trusted Relationship (2)
- Unused/Unsupported Cloud Regions (2)
- Abuse Elevation Control Mechanism (1)
- Account Manipulation (1)
- Cloud Administration Command (1)
- Cloud Infrastructure Discovery (1)
- Cloud Service Discovery (1)
- Data Encrypted for Impact (1)
- Data Manipulation (1)
- Email Collection (1)
- Hide Artifacts (1)
- Masquerading (1)
- Modify Authentication Process (1)
- Network Boundary Bridging (1)
- Remote Services (1)
- Service Stop (1)
- Weaken Encryption (1)
Credential Access
40 detectors
- Unsecured Credentials (29)
- Steal Application Access Token (11)
- Valid Accounts (10)
- Credentials from Password Stores (8)
- Forge Web Credentials (3)
- Account Manipulation (2)
- Cloud Service Discovery (2)
- Data from Cloud Storage (2)
- Exploit Public-Facing Application (2)
- Use Alternate Authentication Material (2)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- Network Sniffing (1)
- OS Credential Dumping (1)
- Trusted Relationship (1)
Discovery
48 detectors
- Cloud Service Discovery (25)
- Cloud Infrastructure Discovery (16)
- Account Discovery (10)
- Permission Groups Discovery (4)
- Container and Resource Discovery (3)
- Credentials from Password Stores (2)
- Abuse Elevation Control Mechanism (1)
- Account Manipulation (1)
- Cloud Administration Command (1)
- Cloud Storage Object Discovery (1)
- Deploy Container (1)
- Log Enumeration (1)
- Network Service Discovery (1)
- Network Sniffing (1)
- Password Policy Discovery (1)
- Remote Services (1)
- Remote System Discovery (1)
- Resource Hijacking (1)
- Software Discovery (1)
- Unused/Unsupported Cloud Regions (1)
- Valid Accounts (1)
Lateral Movement
13 detectors
- Remote Services (10)
- Account Manipulation (3)
- Cloud Administration Command (3)
- Use Alternate Authentication Material (2)
- Valid Accounts (2)
- Cloud Service Discovery (1)
- Command and Scripting Interpreter (1)
- Forge Web Credentials (1)
- Internal Spearphishing (1)
- Modify Cloud Compute Infrastructure (1)
- Network Boundary Bridging (1)
- Steal Application Access Token (1)
- Unsecured Credentials (1)
Collection
20 detectors
- Data from Cloud Storage (16)
- Automated Exfiltration (8)
- Modify Cloud Compute Infrastructure (2)
- Transfer Data to Cloud Account (2)
- Unsecured Credentials (2)
- Automated Collection (1)
- Credentials from Password Stores (1)
- Data Staged (1)
- Data from Information Repositories (1)
- Email Collection (1)
- Indicator Removal (1)
Command and Control
5 detectors
Exfiltration
42 detectors
Impact
64 detectors
- Data Destruction (18)
- Account Access Removal (9)
- Inhibit System Recovery (9)
- Data Manipulation (8)
- Network Denial of Service (8)
- Impair Defenses (6)
- Resource Hijacking (5)
- Valid Accounts (5)
- Service Stop (4)
- Data Encrypted for Impact (3)
- Cloud Service Discovery (1)
- Endpoint Denial of Service (1)
- Network Service Discovery (1)
- System Shutdown/Reboot (1)