Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
50 detectors match the current filters. tactic: TA0008 ✕
Download CSV8 tactics · 21 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
2 detectors
Execution
8 detectors
Persistence
4 detectors
Privilege Escalation
2 detectors
Defense Evasion
2 detectors
Credential Access
5 detectors
Discovery
2 detectors
Lateral Movement
50 detectors
- Remote Services (33)
- Use Alternate Authentication Material (12)
- System Services (4)
- Account Manipulation (3)
- Adversary-in-the-Middle (3)
- Valid Accounts (3)
- Cloud Administration Command (2)
- Command and Scripting Interpreter (2)
- Exploitation of Remote Services (2)
- Internal Spearphishing (2)
- Lateral Tool Transfer (2)
- Brute Force (1)
- Cloud Service Discovery (1)
- Exploit Public-Facing Application (1)
- Forge Web Credentials (1)
- Impair Defenses (1)
- Modify Cloud Compute Infrastructure (1)
- Network Boundary Bridging (1)
- Network Service Discovery (1)
- Scheduled Task/Job (1)
- Windows Management Instrumentation (1)