Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
123 detectors match the current filters. tactic: TA0006 ✕
Download CSV9 tactics · 29 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
2 detectors
Execution
3 detectors
Persistence
2 detectors
Defense Evasion
4 detectors
Credential Access
123 detectors
- OS Credential Dumping (39)
- Unsecured Credentials (31)
- Credentials from Password Stores (18)
- Brute Force (10)
- Adversary-in-the-Middle (6)
- Input Capture (6)
- Steal or Forge Kerberos Tickets (6)
- Modify Authentication Process (4)
- Account Discovery (3)
- Network Sniffing (3)
- Steal or Forge Authentication Certificates (3)
- Use Alternate Authentication Material (3)
- Automated Collection (2)
- Command and Scripting Interpreter (2)
- System Service Discovery (2)
- Valid Accounts (2)
- Defacement (1)
- Exploitation of Remote Services (1)
- File and Directory Discovery (1)
- Forced Authentication (1)
- Forge Web Credentials (1)
- Hide Artifacts (1)
- Inhibit System Recovery (1)
- Network Service Discovery (1)
- Rogue Domain Controller (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Windows Management Instrumentation (1)
Discovery
8 detectors
- Account Discovery (3)
- Network Sniffing (3)
- OS Credential Dumping (3)
- System Service Discovery (2)
- Brute Force (1)
- Credentials from Password Stores (1)
- File and Directory Discovery (1)
- Network Service Discovery (1)
- Steal or Forge Authentication Certificates (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
4 detectors
Collection
6 detectors
Impact
2 detectors