Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
255 detectors match the current filters.
Download CSV13 tactics · 73 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
3 detectors
Initial Access
8 detectors
Execution
33 detectors
Persistence
34 detectors
Privilege Escalation
11 detectors
Defense Evasion
78 detectors
- Impair Defenses (22)
- Indicator Removal (10)
- System Binary Proxy Execution (10)
- Hide Artifacts (7)
- Masquerading (6)
- Subvert Trust Controls (4)
- File and Directory Permissions Modification (3)
- Process Injection (3)
- Virtualization/Sandbox Evasion (3)
- Deobfuscate/Decode Files or Information (2)
- Indirect Command Execution (2)
- Rootkit (2)
- Trusted Developer Utilities Proxy Execution (2)
- Data Destruction (1)
- Inhibit System Recovery (1)
- Obfuscated Files or Information (1)
- System Script Proxy Execution (1)
- Valid Accounts (1)
- Windows Management Instrumentation (1)
Credential Access
29 detectors
Discovery
37 detectors
- Account Discovery (7)
- Remote System Discovery (7)
- System Network Configuration Discovery (5)
- Virtualization/Sandbox Evasion (4)
- Network Share Discovery (3)
- System Information Discovery (3)
- Windows Management Instrumentation (3)
- File and Directory Discovery (2)
- Network Service Discovery (2)
- Network Sniffing (2)
- Password Policy Discovery (2)
- Permission Groups Discovery (2)
- Abuse Elevation Control Mechanism (1)
- Domain Trust Discovery (1)
- Group Policy Discovery (1)
- Software Discovery (1)
- System Owner/User Discovery (1)
- System Service Discovery (1)
Lateral Movement
9 detectors
Collection
17 detectors
Command and Control
4 detectors
Exfiltration
6 detectors