Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
147 detectors match the current filters. tactic: TA0006 ✕
Download CSV11 tactics · 33 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
13 detectors
Initial Access
8 detectors
- Valid Accounts (6)
- Steal Application Access Token (4)
- Unsecured Credentials (3)
- Brute Force (2)
- Forge Web Credentials (2)
- Phishing (2)
- Trusted Relationship (2)
- Account Manipulation (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- User Execution (1)
Execution
12 detectors
Persistence
10 detectors
Privilege Escalation
4 detectors
Defense Evasion
3 detectors
Credential Access
147 detectors
- Unsecured Credentials (43)
- Brute Force (38)
- Credentials from Password Stores (23)
- Compromise Accounts (13)
- User Execution (12)
- OS Credential Dumping (11)
- Valid Accounts (11)
- Steal Application Access Token (10)
- Modify Authentication Process (8)
- Steal or Forge Authentication Certificates (6)
- Account Manipulation (5)
- Adversary-in-the-Middle (5)
- Forge Web Credentials (4)
- Use Alternate Authentication Material (4)
- Account Discovery (3)
- Data from Cloud Storage (3)
- File and Directory Discovery (3)
- Input Capture (3)
- Network Sniffing (3)
- Steal or Forge Kerberos Tickets (3)
- Automated Collection (2)
- Cloud Service Discovery (2)
- Forced Authentication (2)
- Multi-Factor Authentication Request Generation (2)
- Phishing (2)
- Trusted Relationship (2)
- Inhibit System Recovery (1)
- Remote Services (1)
- Rogue Domain Controller (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
Discovery
10 detectors
- Account Discovery (3)
- Credentials from Password Stores (3)
- File and Directory Discovery (3)
- Network Sniffing (3)
- Cloud Service Discovery (2)
- OS Credential Dumping (2)
- Steal or Forge Authentication Certificates (2)
- Brute Force (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
5 detectors
Collection
7 detectors
Impact
1 detector