Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
146 detectors match the current filters.
Download CSV14 tactics · 63 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
3 detectors
Resource Development
8 detectors
Initial Access
21 detectors
Execution
5 detectors
Persistence
7 detectors
Privilege Escalation
6 detectors
Defense Evasion
3 detectors
Credential Access
37 detectors
- Brute Force (20)
- Compromise Accounts (7)
- Unsecured Credentials (6)
- Adversary-in-the-Middle (4)
- Valid Accounts (4)
- Data from Cloud Storage (3)
- Steal or Forge Kerberos Tickets (3)
- Use Alternate Authentication Material (3)
- Credentials from Password Stores (2)
- Steal Application Access Token (2)
- User Execution (2)
- Account Discovery (1)
- Account Manipulation (1)
- Multi-Factor Authentication Request Generation (1)
- Phishing (1)
- Remote Services (1)
- Steal or Forge Authentication Certificates (1)
Discovery
41 detectors
- Cloud Service Discovery (14)
- Account Discovery (11)
- Cloud Infrastructure Discovery (11)
- Permission Groups Discovery (6)
- Remote System Discovery (5)
- System Network Configuration Discovery (4)
- Container and Resource Discovery (3)
- System Information Discovery (3)
- System Service Discovery (3)
- Log Enumeration (2)
- Network Service Discovery (2)
- Valid Accounts (2)
- Abuse Elevation Control Mechanism (1)
- Brute Force (1)
- Cloud Service Dashboard (1)
- Cloud Storage Object Discovery (1)
- Domain Trust Discovery (1)
- File and Directory Discovery (1)
- Software Discovery (1)
- Unused/Unsupported Cloud Regions (1)
Lateral Movement
11 detectors
Collection
18 detectors
- Data Staged (7)
- Data from Cloud Storage (7)
- Unsecured Credentials (3)
- Automated Collection (2)
- Data from Information Repositories (2)
- Exfiltration Over Physical Medium (2)
- Archive Collected Data (1)
- Automated Exfiltration (1)
- Credentials from Password Stores (1)
- Data from Local System (1)
- Data from Network Shared Drive (1)
- Email Collection (1)
- Exfiltration Over Alternative Protocol (1)
- Exfiltration Over Web Service (1)
- Screen Capture (1)
- Transfer Data to Cloud Account (1)
Command and Control
6 detectors
Exfiltration
12 detectors