Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
61 detectors match the current filters. tactic: TA0001 ✕ technique: T1078 ✕
Download CSV12 tactics · 21 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
2 detectors
Initial Access
61 detectors
- Valid Accounts (61)
- Trusted Relationship (5)
- Account Manipulation (4)
- Unsecured Credentials (3)
- Abuse Elevation Control Mechanism (2)
- Brute Force (2)
- Cloud Service Discovery (2)
- Compromise Accounts (2)
- Forge Web Credentials (2)
- Resource Hijacking (2)
- Steal Application Access Token (2)
- Automated Collection (1)
- Automated Exfiltration (1)
- Cloud Service Dashboard (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Proxy (1)
- Remote Services (1)
Persistence
8 detectors
Privilege Escalation
7 detectors
Defense Evasion
3 detectors
Credential Access
6 detectors
Discovery
2 detectors
Lateral Movement
1 detector
Collection
1 detector
Command and Control
1 detector
Exfiltration
1 detector
Impact
3 detectors