Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
131 detectors match the current filters. tactic: TA0003 ✕
Download CSV9 tactics · 30 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
4 detectors
Execution
9 detectors
Persistence
131 detectors
- Boot or Logon Autostart Execution (36)
- Event Triggered Execution (20)
- Scheduled Task/Job (16)
- Create or Modify System Process (14)
- Hijack Execution Flow (9)
- Server Software Component (9)
- Software Extensions (6)
- Account Manipulation (5)
- Create Account (5)
- External Remote Services (4)
- BITS Jobs (3)
- Remote Services (3)
- Boot or Logon Initialization Scripts (2)
- Masquerading (2)
- Modify Authentication Process (2)
- Permission Groups Discovery (2)
- Pre-OS Boot (2)
- Process Injection (2)
- System Services (2)
- Account Discovery (1)
- Application Layer Protocol (1)
- Browser Extensions (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Escape to Host (1)
- Office Application Startup (1)
- Replication Through Removable Media (1)
- System Binary Proxy Execution (1)
- User Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
18 detectors
Defense Evasion
11 detectors
Credential Access
2 detectors
Discovery
3 detectors
Lateral Movement
4 detectors
Command and Control
1 detector