Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
474 detectors match the current filters.
Download CSV14 tactics · 105 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
2 detectors
Resource Development
4 detectors
Initial Access
18 detectors
Execution
68 detectors
- Command and Scripting Interpreter (28)
- System Services (12)
- User Execution (12)
- Windows Management Instrumentation (9)
- Remote Services (6)
- Container Administration Command (4)
- Obtain Capabilities (3)
- System Information Discovery (3)
- Exploitation for Client Execution (2)
- Native API (2)
- Account Discovery (1)
- Data from Local System (1)
- Deploy Container (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- Impair Defenses (1)
- Lateral Tool Transfer (1)
- Scheduled Task/Job (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Valid Accounts (1)
Persistence
68 detectors
- Boot or Logon Autostart Execution (16)
- Event Triggered Execution (14)
- Scheduled Task/Job (8)
- Create or Modify System Process (6)
- Create Account (5)
- Hijack Execution Flow (5)
- Server Software Component (4)
- Software Extensions (4)
- Modify Authentication Process (2)
- Permission Groups Discovery (2)
- Account Discovery (1)
- Account Manipulation (1)
- Application Layer Protocol (1)
- BITS Jobs (1)
- Compromise Host Software Binary (1)
- External Remote Services (1)
- Office Application Startup (1)
- Pre-OS Boot (1)
- Process Injection (1)
- Remote Services (1)
- System Binary Proxy Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
23 detectors
- Abuse Elevation Control Mechanism (9)
- Escape to Host (4)
- Hijack Execution Flow (4)
- Event Triggered Execution (2)
- Valid Accounts (2)
- Account Discovery (1)
- Boot or Logon Autostart Execution (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Exploitation for Privilege Escalation (1)
- System Services (1)
Defense Evasion
126 detectors
- Impair Defenses (25)
- System Binary Proxy Execution (16)
- Masquerading (15)
- Indicator Removal (11)
- Hide Artifacts (10)
- Process Injection (8)
- Virtualization/Sandbox Evasion (7)
- Hijack Execution Flow (5)
- Obfuscated Files or Information (5)
- Subvert Trust Controls (5)
- Deobfuscate/Decode Files or Information (4)
- File and Directory Permissions Modification (3)
- Rootkit (3)
- Valid Accounts (3)
- Indirect Command Execution (2)
- Modify Authentication Process (2)
- Trusted Developer Utilities Proxy Execution (2)
- Abuse Elevation Control Mechanism (1)
- Application Layer Protocol (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Inhibit System Recovery (1)
- Reflective Code Loading (1)
- System Script Proxy Execution (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
55 detectors
- Unsecured Credentials (18)
- Credentials from Password Stores (15)
- OS Credential Dumping (9)
- Modify Authentication Process (4)
- Brute Force (3)
- Input Capture (3)
- Account Discovery (2)
- Adversary-in-the-Middle (2)
- Automated Collection (2)
- Network Sniffing (2)
- File and Directory Discovery (1)
- Inhibit System Recovery (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Use Alternate Authentication Material (1)
Discovery
74 detectors
- Account Discovery (18)
- Remote System Discovery (12)
- System Information Discovery (9)
- System Network Configuration Discovery (9)
- Permission Groups Discovery (7)
- Virtualization/Sandbox Evasion (7)
- System Service Discovery (6)
- Container and Resource Discovery (5)
- Network Service Discovery (5)
- System Owner/User Discovery (5)
- Windows Management Instrumentation (5)
- File and Directory Discovery (4)
- Network Share Discovery (4)
- Create Account (3)
- Network Sniffing (3)
- OS Credential Dumping (2)
- Password Policy Discovery (2)
- Process Discovery (2)
- Abuse Elevation Control Mechanism (1)
- Browser Information Discovery (1)
- Credentials from Password Stores (1)
- Domain Trust Discovery (1)
- Escape to Host (1)
- Group Policy Discovery (1)
- Remote Services (1)
- Software Discovery (1)
- System Network Connections Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
25 detectors
- Remote Services (21)
- System Services (4)
- Exploitation of Remote Services (2)
- Lateral Tool Transfer (2)
- Adversary-in-the-Middle (1)
- Command and Scripting Interpreter (1)
- Exploit Public-Facing Application (1)
- Network Service Discovery (1)
- Scheduled Task/Job (1)
- Use Alternate Authentication Material (1)
- Windows Management Instrumentation (1)
Collection
21 detectors
Command and Control
33 detectors
- Application Layer Protocol (19)
- Web Service (5)
- Non-Standard Port (4)
- Exfiltration Over Web Service (2)
- Non-Application Layer Protocol (2)
- Phishing (2)
- Protocol Tunneling (2)
- Proxy (2)
- Trusted Relationship (2)
- Data Encoding (1)
- Exfiltration Over Alternative Protocol (1)
- Exfiltration Over C2 Channel (1)
- Ingress Tool Transfer (1)
- Masquerading (1)
- Remote Access Tools (1)
- Software Extensions (1)
- System Binary Proxy Execution (1)
Exfiltration
18 detectors