Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
247 detectors match the current filters. tactic: TA0005 ✕
Download CSV12 tactics · 53 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
6 detectors
Execution
9 detectors
Persistence
15 detectors
- Hijack Execution Flow (5)
- Account Manipulation (4)
- Impair Defenses (3)
- Modify Authentication Process (3)
- Use Alternate Authentication Material (3)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Domain or Tenant Policy Modification (1)
- Process Injection (1)
- System Binary Proxy Execution (1)
- Valid Accounts (1)
Privilege Escalation
9 detectors
Defense Evasion
247 detectors
- Impair Defenses (81)
- Masquerading (23)
- Indicator Removal (17)
- Hide Artifacts (16)
- System Binary Proxy Execution (16)
- Impersonation (13)
- Valid Accounts (12)
- Modify Cloud Compute Infrastructure (10)
- Process Injection (8)
- Modify Authentication Process (7)
- Virtualization/Sandbox Evasion (7)
- Hijack Execution Flow (6)
- User Execution (6)
- Abuse Elevation Control Mechanism (5)
- File and Directory Permissions Modification (5)
- Obfuscated Files or Information (5)
- Subvert Trust Controls (5)
- Account Manipulation (4)
- Data Destruction (4)
- Deobfuscate/Decode Files or Information (4)
- Domain or Tenant Policy Modification (3)
- Rootkit (3)
- Use Alternate Authentication Material (3)
- Command and Scripting Interpreter (2)
- Data from Cloud Storage (2)
- Indirect Command Execution (2)
- Phishing (2)
- Remote Services (2)
- Transfer Data to Cloud Account (2)
- Trusted Developer Utilities Proxy Execution (2)
- Trusted Relationship (2)
- Unused/Unsupported Cloud Regions (2)
- Access Token Manipulation (1)
- Application Layer Protocol (1)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Cloud Infrastructure Discovery (1)
- Cloud Service Discovery (1)
- Compromise Host Software Binary (1)
- Data Encrypted for Impact (1)
- Data Manipulation (1)
- Email Collection (1)
- Exfiltration Over Alternative Protocol (1)
- Inhibit System Recovery (1)
- Network Boundary Bridging (1)
- OS Credential Dumping (1)
- Reflective Code Loading (1)
- Rogue Domain Controller (1)
- Service Stop (1)
- System Script Proxy Execution (1)
- Weaken Encryption (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
3 detectors
Discovery
5 detectors
Lateral Movement
2 detectors
Collection
3 detectors
Command and Control
2 detectors
Exfiltration
3 detectors