Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
126 detectors match the current filters. tactic: TA0005 ✕
Download CSV8 tactics · 26 techniques · cell shade = number of matching detectors; click a cell to list them.
Execution
1 detector
Persistence
7 detectors
Privilege Escalation
4 detectors
Defense Evasion
126 detectors
- Impair Defenses (25)
- System Binary Proxy Execution (16)
- Masquerading (15)
- Indicator Removal (11)
- Hide Artifacts (10)
- Process Injection (8)
- Virtualization/Sandbox Evasion (7)
- Hijack Execution Flow (5)
- Obfuscated Files or Information (5)
- Subvert Trust Controls (5)
- Deobfuscate/Decode Files or Information (4)
- File and Directory Permissions Modification (3)
- Rootkit (3)
- Valid Accounts (3)
- Indirect Command Execution (2)
- Modify Authentication Process (2)
- Trusted Developer Utilities Proxy Execution (2)
- Abuse Elevation Control Mechanism (1)
- Application Layer Protocol (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Inhibit System Recovery (1)
- Reflective Code Loading (1)
- System Script Proxy Execution (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
2 detectors
Discovery
4 detectors
Command and Control
2 detectors
Impact
2 detectors