Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
687 detectors match the current filters.
Download CSV14 tactics · 125 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
7 detectors
Resource Development
13 detectors
Initial Access
82 detectors
- Valid Accounts (49)
- Phishing (20)
- Trusted Relationship (10)
- External Remote Services (5)
- Phishing for Information (5)
- Account Manipulation (4)
- User Execution (4)
- Exfiltration Over Alternative Protocol (3)
- Steal Application Access Token (3)
- Unsecured Credentials (3)
- Abuse Elevation Control Mechanism (2)
- Exploit Public-Facing Application (2)
- Forge Web Credentials (2)
- Impersonation (2)
- Modify Authentication Process (2)
- Automated Collection (1)
- Automated Exfiltration (1)
- Brute Force (1)
- Cloud Service Discovery (1)
- Compromise Accounts (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- Exploitation of Remote Services (1)
- Hardware Additions (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Proxy (1)
- Remote Services (1)
- Server Software Component (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
Execution
85 detectors
- User Execution (28)
- Command and Scripting Interpreter (24)
- Deploy Container (12)
- Brute Force (10)
- Escape to Host (6)
- Cloud Administration Command (5)
- Container Administration Command (5)
- Remote Services (5)
- System Services (5)
- Windows Management Instrumentation (5)
- Masquerading (4)
- Phishing (4)
- Serverless Execution (3)
- Account Manipulation (2)
- Event Triggered Execution (2)
- Impair Defenses (2)
- Scheduled Task/Job (2)
- Access Token Manipulation (1)
- Account Discovery (1)
- Automated Exfiltration (1)
- Data from Local System (1)
- Hide Artifacts (1)
- Impersonation (1)
- Lateral Tool Transfer (1)
- Remote System Discovery (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Valid Accounts (1)
Persistence
139 detectors
- Account Manipulation (66)
- Valid Accounts (38)
- Create Account (10)
- Scheduled Task/Job (8)
- Boot or Logon Autostart Execution (6)
- Hijack Execution Flow (6)
- Modify Authentication Process (6)
- Cloud Application Integration (4)
- Event Triggered Execution (4)
- External Remote Services (4)
- Software Extensions (4)
- Use Alternate Authentication Material (4)
- Command and Scripting Interpreter (3)
- Impair Defenses (3)
- Remote Services (3)
- Create or Modify System Process (2)
- Domain or Tenant Policy Modification (2)
- Forge Web Credentials (2)
- Permission Groups Discovery (2)
- Access Token Manipulation (1)
- Account Discovery (1)
- Automated Exfiltration (1)
- Cloud Administration Command (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Exfiltration Over Alternative Protocol (1)
- Multi-Factor Authentication Request Generation (1)
- Process Injection (1)
- Server Software Component (1)
- Serverless Execution (1)
- Steal or Forge Authentication Certificates (1)
- Supply Chain Compromise (1)
- System Binary Proxy Execution (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
- Windows Management Instrumentation (1)
Privilege Escalation
79 detectors
- Account Manipulation (39)
- Valid Accounts (28)
- Escape to Host (9)
- Abuse Elevation Control Mechanism (5)
- Deploy Container (5)
- Domain or Tenant Policy Modification (5)
- Hijack Execution Flow (5)
- Access Token Manipulation (2)
- Trusted Relationship (2)
- Use Alternate Authentication Material (2)
- Cloud Infrastructure Discovery (1)
- Command and Scripting Interpreter (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Data Destruction (1)
- Event Triggered Execution (1)
- Steal or Forge Authentication Certificates (1)
- System Services (1)
Defense Evasion
166 detectors
- Impair Defenses (59)
- Masquerading (17)
- Impersonation (13)
- Modify Cloud Compute Infrastructure (10)
- Valid Accounts (10)
- Hide Artifacts (9)
- Modify Authentication Process (7)
- Hijack Execution Flow (6)
- Indicator Removal (6)
- System Binary Proxy Execution (6)
- User Execution (6)
- Abuse Elevation Control Mechanism (5)
- Process Injection (5)
- Account Manipulation (4)
- Obfuscated Files or Information (4)
- Virtualization/Sandbox Evasion (4)
- Data Destruction (3)
- Domain or Tenant Policy Modification (3)
- Use Alternate Authentication Material (3)
- Command and Scripting Interpreter (2)
- Data from Cloud Storage (2)
- Deobfuscate/Decode Files or Information (2)
- File and Directory Permissions Modification (2)
- Phishing (2)
- Remote Services (2)
- Transfer Data to Cloud Account (2)
- Trusted Relationship (2)
- Access Token Manipulation (1)
- Application Layer Protocol (1)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Compromise Host Software Binary (1)
- Data Encrypted for Impact (1)
- Data Manipulation (1)
- Email Collection (1)
- Exfiltration Over Alternative Protocol (1)
- Network Boundary Bridging (1)
- OS Credential Dumping (1)
- Reflective Code Loading (1)
- Rogue Domain Controller (1)
- Rootkit (1)
- Service Stop (1)
- Subvert Trust Controls (1)
- Unused/Unsupported Cloud Regions (1)
- Weaken Encryption (1)
- Web Service (1)
Credential Access
81 detectors
- Unsecured Credentials (29)
- Brute Force (17)
- Credentials from Password Stores (12)
- User Execution (10)
- Steal Application Access Token (8)
- Valid Accounts (7)
- Compromise Accounts (6)
- Modify Authentication Process (6)
- OS Credential Dumping (6)
- Steal or Forge Authentication Certificates (5)
- Account Manipulation (4)
- Forge Web Credentials (4)
- File and Directory Discovery (3)
- Account Discovery (2)
- Cloud Service Discovery (2)
- Forced Authentication (2)
- Network Sniffing (2)
- Trusted Relationship (2)
- Adversary-in-the-Middle (1)
- Multi-Factor Authentication Request Generation (1)
- Phishing (1)
- Rogue Domain Controller (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
- Use Alternate Authentication Material (1)
Discovery
55 detectors
- Account Discovery (16)
- Cloud Service Discovery (10)
- Permission Groups Discovery (6)
- Cloud Infrastructure Discovery (5)
- Container and Resource Discovery (4)
- File and Directory Discovery (4)
- System Owner/User Discovery (4)
- Create Account (3)
- Credentials from Password Stores (3)
- Remote System Discovery (3)
- System Information Discovery (3)
- Virtualization/Sandbox Evasion (3)
- Network Sniffing (2)
- OS Credential Dumping (2)
- Process Discovery (2)
- Remote Services (2)
- Steal or Forge Authentication Certificates (2)
- System Network Configuration Discovery (2)
- System Service Discovery (2)
- Windows Management Instrumentation (2)
- Account Manipulation (1)
- Browser Information Discovery (1)
- Cloud Administration Command (1)
- Domain Trust Discovery (1)
- Escape to Host (1)
- Group Policy Discovery (1)
- Network Service Discovery (1)
- Network Share Discovery (1)
- Password Policy Discovery (1)
- System Network Connections Discovery (1)
- System Time Discovery (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Lateral Movement
30 detectors
- Remote Services (21)
- Use Alternate Authentication Material (6)
- Account Manipulation (3)
- Valid Accounts (3)
- Cloud Administration Command (2)
- Command and Scripting Interpreter (2)
- Exploitation of Remote Services (2)
- Cloud Service Discovery (1)
- Exploit Public-Facing Application (1)
- Forge Web Credentials (1)
- Impair Defenses (1)
- Internal Spearphishing (1)
- Lateral Tool Transfer (1)
- Modify Cloud Compute Infrastructure (1)
- Network Boundary Bridging (1)
- Network Service Discovery (1)
- Scheduled Task/Job (1)
- System Services (1)
- Windows Management Instrumentation (1)
Collection
30 detectors
- Data from Cloud Storage (9)
- Email Collection (7)
- Data Staged (6)
- Data from Information Repositories (6)
- Automated Exfiltration (5)
- Archive Collected Data (2)
- Automated Collection (2)
- Exfiltration Over Physical Medium (2)
- Modify Cloud Compute Infrastructure (2)
- Clipboard Data (1)
- Command and Scripting Interpreter (1)
- Data from Local System (1)
- Indicator Removal (1)
- Transfer Data to Cloud Account (1)
- Valid Accounts (1)
Command and Control
26 detectors
- Application Layer Protocol (13)
- Web Service (4)
- Proxy (3)
- Exfiltration Over Web Service (2)
- Non-Application Layer Protocol (2)
- Non-Standard Port (2)
- Remote Access Tools (2)
- Exfiltration Over C2 Channel (1)
- Ingress Tool Transfer (1)
- Masquerading (1)
- Protocol Tunneling (1)
- System Binary Proxy Execution (1)
- Valid Accounts (1)
Exfiltration
48 detectors
- Transfer Data to Cloud Account (24)
- Exfiltration Over Alternative Protocol (10)
- Automated Exfiltration (7)
- Data from Cloud Storage (5)
- Exfiltration Over Web Service (3)
- Phishing (3)
- Application Layer Protocol (2)
- Data Staged (2)
- Exfiltration Over Physical Medium (2)
- Modify Cloud Compute Infrastructure (2)
- Command and Scripting Interpreter (1)
- Data Transfer Size Limits (1)
- Email Collection (1)
- Event Triggered Execution (1)
- Exfiltration Over C2 Channel (1)
- External Remote Services (1)
- Impair Defenses (1)
- Remote Access Tools (1)
- Valid Accounts (1)
- Web Service (1)