Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
153 detectors match the current filters.
Download CSV13 tactics · 53 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
2 detectors
Initial Access
29 detectors
- Valid Accounts (14)
- Phishing (12)
- Impair Defenses (4)
- Steal Application Access Token (2)
- Trusted Relationship (2)
- Account Manipulation (1)
- Automated Collection (1)
- Automated Exfiltration (1)
- Cloud Service Dashboard (1)
- Cloud Service Discovery (1)
- Domain or Tenant Policy Modification (1)
- External Remote Services (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
- User Execution (1)
Execution
4 detectors
Persistence
33 detectors
- Account Manipulation (16)
- Valid Accounts (10)
- Cloud Application Integration (4)
- Modify Authentication Process (4)
- Domain or Tenant Policy Modification (3)
- Command and Scripting Interpreter (2)
- Impair Defenses (2)
- Use Alternate Authentication Material (2)
- Access Token Manipulation (1)
- Automated Exfiltration (1)
- Create Account (1)
- Event Triggered Execution (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
Privilege Escalation
16 detectors
Defense Evasion
35 detectors
- Impair Defenses (18)
- Abuse Elevation Control Mechanism (5)
- Modify Authentication Process (5)
- Phishing (4)
- Domain or Tenant Policy Modification (3)
- Hide Artifacts (3)
- Valid Accounts (3)
- Account Manipulation (2)
- Indicator Removal (2)
- Use Alternate Authentication Material (2)
- Cloud Application Integration (1)
- Data Manipulation (1)
- Exfiltration Over Alternative Protocol (1)
- Remote Services (1)
Credential Access
12 detectors
- Modify Authentication Process (5)
- Steal Application Access Token (3)
- Forge Web Credentials (2)
- Phishing (2)
- Account Manipulation (1)
- Data from Cloud Storage (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
- User Execution (1)
Discovery
3 detectors
Lateral Movement
3 detectors
Collection
32 detectors
- Data Staged (14)
- Email Collection (8)
- Data from Information Repositories (6)
- Exfiltration Over Physical Medium (5)
- Archive Collected Data (4)
- Automated Exfiltration (4)
- Data from Cloud Storage (4)
- Automated Collection (3)
- Data from Local System (1)
- Data from Network Shared Drive (1)
- Exfiltration Over Alternative Protocol (1)
- Exfiltration Over Web Service (1)
- Screen Capture (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Command and Control
2 detectors
Exfiltration
18 detectors
- Automated Exfiltration (6)
- Data Staged (6)
- Exfiltration Over Physical Medium (6)
- Email Collection (5)
- Exfiltration Over Web Service (3)
- Exfiltration Over Alternative Protocol (2)
- Command and Scripting Interpreter (1)
- Event Triggered Execution (1)
- Impair Defenses (1)
- Transfer Data to Cloud Account (1)
- Valid Accounts (1)