Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
215 detectors match the current filters. tactic: TA0005 ✕
Download CSV11 tactics · 42 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
6 detectors
Persistence
11 detectors
Privilege Escalation
11 detectors
Defense Evasion
215 detectors
- System Binary Proxy Execution (40)
- Impair Defenses (38)
- Masquerading (21)
- Process Injection (19)
- Indicator Removal (18)
- Hide Artifacts (14)
- Obfuscated Files or Information (13)
- Hijack Execution Flow (9)
- Virtualization/Sandbox Evasion (7)
- Deobfuscate/Decode Files or Information (6)
- Rootkit (5)
- Subvert Trust Controls (5)
- Trusted Developer Utilities Proxy Execution (5)
- Abuse Elevation Control Mechanism (3)
- Application Layer Protocol (3)
- File and Directory Permissions Modification (3)
- Indirect Command Execution (3)
- System Script Proxy Execution (3)
- User Execution (3)
- Valid Accounts (3)
- Access Token Manipulation (2)
- Command and Scripting Interpreter (2)
- Create or Modify System Process (2)
- Inhibit System Recovery (2)
- Modify Authentication Process (2)
- OS Credential Dumping (2)
- Reflective Code Loading (2)
- BITS Jobs (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Data Encrypted for Impact (1)
- Exfiltration Over Alternative Protocol (1)
- Exploitation for Defense Evasion (1)
- Ingress Tool Transfer (1)
- Modify Registry (1)
- Phishing (1)
- Proxy (1)
- Remote Services (1)
- Rogue Domain Controller (1)
- Scheduled Task/Job (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
4 detectors
Discovery
4 detectors
Lateral Movement
1 detector
Command and Control
6 detectors
Exfiltration
1 detector