Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
895 detectors match the current filters.
Download CSV14 tactics · 127 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
5 detectors
Resource Development
4 detectors
Initial Access
37 detectors
- Phishing (18)
- Exploit Public-Facing Application (8)
- Valid Accounts (5)
- Application Layer Protocol (4)
- External Remote Services (4)
- Server Software Component (4)
- User Execution (4)
- Exfiltration Over Alternative Protocol (3)
- Trusted Relationship (3)
- Brute Force (2)
- Data from Information Repositories (2)
- Non-Standard Port (2)
- Command and Scripting Interpreter (1)
- Exploitation of Remote Services (1)
- Hardware Additions (1)
- Process Injection (1)
- Supply Chain Compromise (1)
Execution
138 detectors
- Command and Scripting Interpreter (56)
- User Execution (30)
- System Services (22)
- Windows Management Instrumentation (13)
- Remote Services (12)
- Scheduled Task/Job (7)
- Native API (5)
- Container Administration Command (4)
- Phishing (4)
- Create or Modify System Process (3)
- Exploitation for Client Execution (3)
- Obtain Capabilities (3)
- System Information Discovery (3)
- Boot or Logon Autostart Execution (2)
- Credentials from Password Stores (2)
- Data from Local System (2)
- Deploy Container (2)
- Account Discovery (1)
- Application Layer Protocol (1)
- Automated Exfiltration (1)
- Clipboard Data (1)
- Container and Resource Discovery (1)
- Deobfuscate/Decode Files or Information (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Hijack Execution Flow (1)
- Impair Defenses (1)
- Lateral Tool Transfer (1)
- Masquerading (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- System Binary Proxy Execution (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Persistence
131 detectors
- Boot or Logon Autostart Execution (36)
- Event Triggered Execution (20)
- Scheduled Task/Job (16)
- Create or Modify System Process (14)
- Hijack Execution Flow (9)
- Server Software Component (9)
- Software Extensions (6)
- Account Manipulation (5)
- Create Account (5)
- External Remote Services (4)
- BITS Jobs (3)
- Remote Services (3)
- Boot or Logon Initialization Scripts (2)
- Masquerading (2)
- Modify Authentication Process (2)
- Permission Groups Discovery (2)
- Pre-OS Boot (2)
- Process Injection (2)
- System Services (2)
- Account Discovery (1)
- Application Layer Protocol (1)
- Browser Extensions (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Escape to Host (1)
- Office Application Startup (1)
- Replication Through Removable Media (1)
- System Binary Proxy Execution (1)
- User Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
62 detectors
- Abuse Elevation Control Mechanism (20)
- Escape to Host (8)
- Hijack Execution Flow (7)
- Boot or Logon Autostart Execution (6)
- Event Triggered Execution (5)
- Create or Modify System Process (3)
- Exploitation for Privilege Escalation (3)
- Scheduled Task/Job (3)
- Valid Accounts (3)
- Access Token Manipulation (2)
- Process Injection (2)
- System Services (2)
- Account Discovery (1)
- Boot or Logon Initialization Scripts (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- User Execution (1)
Defense Evasion
215 detectors
- System Binary Proxy Execution (40)
- Impair Defenses (38)
- Masquerading (21)
- Process Injection (19)
- Indicator Removal (18)
- Hide Artifacts (14)
- Obfuscated Files or Information (13)
- Hijack Execution Flow (9)
- Virtualization/Sandbox Evasion (7)
- Deobfuscate/Decode Files or Information (6)
- Rootkit (5)
- Subvert Trust Controls (5)
- Trusted Developer Utilities Proxy Execution (5)
- Abuse Elevation Control Mechanism (3)
- Application Layer Protocol (3)
- File and Directory Permissions Modification (3)
- Indirect Command Execution (3)
- System Script Proxy Execution (3)
- User Execution (3)
- Valid Accounts (3)
- Access Token Manipulation (2)
- Command and Scripting Interpreter (2)
- Create or Modify System Process (2)
- Inhibit System Recovery (2)
- Modify Authentication Process (2)
- OS Credential Dumping (2)
- Reflective Code Loading (2)
- BITS Jobs (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Data Encrypted for Impact (1)
- Exfiltration Over Alternative Protocol (1)
- Exploitation for Defense Evasion (1)
- Ingress Tool Transfer (1)
- Modify Registry (1)
- Phishing (1)
- Proxy (1)
- Remote Services (1)
- Rogue Domain Controller (1)
- Scheduled Task/Job (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
123 detectors
- OS Credential Dumping (39)
- Unsecured Credentials (31)
- Credentials from Password Stores (18)
- Brute Force (10)
- Adversary-in-the-Middle (6)
- Input Capture (6)
- Steal or Forge Kerberos Tickets (6)
- Modify Authentication Process (4)
- Account Discovery (3)
- Network Sniffing (3)
- Steal or Forge Authentication Certificates (3)
- Use Alternate Authentication Material (3)
- Automated Collection (2)
- Command and Scripting Interpreter (2)
- System Service Discovery (2)
- Valid Accounts (2)
- Defacement (1)
- Exploitation of Remote Services (1)
- File and Directory Discovery (1)
- Forced Authentication (1)
- Forge Web Credentials (1)
- Hide Artifacts (1)
- Inhibit System Recovery (1)
- Network Service Discovery (1)
- Rogue Domain Controller (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Windows Management Instrumentation (1)
Discovery
110 detectors
- Account Discovery (25)
- Remote System Discovery (19)
- System Network Configuration Discovery (15)
- System Information Discovery (12)
- Network Service Discovery (11)
- System Service Discovery (10)
- Permission Groups Discovery (8)
- Container and Resource Discovery (7)
- File and Directory Discovery (7)
- Virtualization/Sandbox Evasion (7)
- Network Share Discovery (5)
- System Owner/User Discovery (5)
- Windows Management Instrumentation (5)
- Network Sniffing (4)
- Browser Information Discovery (3)
- Create Account (3)
- OS Credential Dumping (3)
- Password Policy Discovery (2)
- Process Discovery (2)
- Abuse Elevation Control Mechanism (1)
- Automated Collection (1)
- Brute Force (1)
- Credentials from Password Stores (1)
- Data from Local System (1)
- Deploy Container (1)
- Domain Trust Discovery (1)
- Escape to Host (1)
- Group Policy Discovery (1)
- Remote Services (1)
- Software Discovery (1)
- Steal or Forge Authentication Certificates (1)
- System Network Connections Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
62 detectors
- Remote Services (50)
- System Services (8)
- Use Alternate Authentication Material (6)
- Exploitation of Remote Services (3)
- Adversary-in-the-Middle (2)
- Command and Scripting Interpreter (2)
- Lateral Tool Transfer (2)
- Remote Access Tools (2)
- Scheduled Task/Job (2)
- Windows Management Instrumentation (2)
- Create or Modify System Process (1)
- Exploit Public-Facing Application (1)
- Forge Web Credentials (1)
- Hijack Execution Flow (1)
- Impair Defenses (1)
- Network Service Discovery (1)
- Remote Service Session Hijacking (1)
- Replication Through Removable Media (1)
- Steal or Forge Kerberos Tickets (1)
Collection
39 detectors
- Archive Collected Data (8)
- Data Staged (6)
- Data from Local System (6)
- Data from Information Repositories (4)
- Input Capture (4)
- Audio Capture (3)
- Automated Collection (3)
- Command and Scripting Interpreter (3)
- Email Collection (3)
- Screen Capture (3)
- Clipboard Data (2)
- OS Credential Dumping (2)
- Valid Accounts (2)
- Browser Information Discovery (1)
- Gather Victim Host Information (1)
- Video Capture (1)
Command and Control
73 detectors
- Application Layer Protocol (39)
- Web Service (8)
- Non-Standard Port (6)
- Protocol Tunneling (6)
- Proxy (5)
- Exfiltration Over Web Service (4)
- Ingress Tool Transfer (4)
- Non-Application Layer Protocol (4)
- Remote Access Tools (4)
- System Binary Proxy Execution (4)
- Dynamic Resolution (2)
- Exfiltration Over Alternative Protocol (2)
- Phishing (2)
- Remote Services (2)
- Trusted Relationship (2)
- Command and Scripting Interpreter (1)
- Data Encoding (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Impair Defenses (1)
- Masquerading (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
Exfiltration
31 detectors
- Exfiltration Over Alternative Protocol (21)
- Exfiltration Over Web Service (5)
- Application Layer Protocol (4)
- Phishing (3)
- Web Service (3)
- Automated Exfiltration (2)
- Command and Scripting Interpreter (2)
- Exfiltration Over C2 Channel (2)
- BITS Jobs (1)
- Data Transfer Size Limits (1)
- Remote Access Tools (1)
Impact
29 detectors
- Inhibit System Recovery (10)
- Service Stop (8)
- Network Denial of Service (6)
- Data Destruction (3)
- Data Encrypted for Impact (2)
- Defacement (2)
- Resource Hijacking (2)
- Rootkit (2)
- System Shutdown/Reboot (2)
- Endpoint Denial of Service (1)
- Indicator Removal (1)
- Input Capture (1)
- OS Credential Dumping (1)
- Obfuscated Files or Information (1)