Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
38 detectors match the current filters. tactic: TA0001 ✕
Download CSV9 tactics · 19 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
38 detectors
- Valid Accounts (31)
- Unsecured Credentials (9)
- Trusted Relationship (8)
- Steal Application Access Token (6)
- Resource Hijacking (3)
- Abuse Elevation Control Mechanism (2)
- Account Manipulation (2)
- Exploit Public-Facing Application (2)
- External Remote Services (2)
- Forge Web Credentials (2)
- Modify Authentication Process (2)
- Proxy (2)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Remote Services (1)
- Use Alternate Authentication Material (1)
Execution
1 detector
Persistence
4 detectors
Privilege Escalation
5 detectors
Defense Evasion
4 detectors
Credential Access
11 detectors
- Unsecured Credentials (9)
- Valid Accounts (9)
- Steal Application Access Token (6)
- Exploit Public-Facing Application (2)
- Forge Web Credentials (2)
- Account Manipulation (1)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Trusted Relationship (1)
- Use Alternate Authentication Material (1)
Lateral Movement
2 detectors
Command and Control
2 detectors
Impact
4 detectors