Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
70 detectors match the current filters. tactic: TA0005 ✕
Download CSV10 tactics · 26 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
4 detectors
Execution
2 detectors
Persistence
2 detectors
Privilege Escalation
3 detectors
Defense Evasion
70 detectors
- Impair Defenses (46)
- Modify Cloud Compute Infrastructure (10)
- Data Destruction (3)
- Indicator Removal (3)
- Valid Accounts (3)
- Command and Scripting Interpreter (2)
- Data from Cloud Storage (2)
- Domain or Tenant Policy Modification (2)
- File and Directory Permissions Modification (2)
- Transfer Data to Cloud Account (2)
- Trusted Relationship (2)
- Unused/Unsupported Cloud Regions (2)
- Abuse Elevation Control Mechanism (1)
- Account Manipulation (1)
- Cloud Administration Command (1)
- Cloud Infrastructure Discovery (1)
- Cloud Service Discovery (1)
- Data Encrypted for Impact (1)
- Email Collection (1)
- Hide Artifacts (1)
- Masquerading (1)
- Modify Authentication Process (1)
- Network Boundary Bridging (1)
- Remote Services (1)
- Service Stop (1)
- Weaken Encryption (1)
Discovery
1 detector
Lateral Movement
1 detector
Collection
3 detectors
Exfiltration
2 detectors
Impact
5 detectors