Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
382 detectors match the current filters.
Download CSV14 tactics · 113 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
5 detectors
Resource Development
3 detectors
Initial Access
44 detectors
- Valid Accounts (21)
- Phishing (17)
- User Execution (5)
- Impair Defenses (4)
- Steal Application Access Token (4)
- Unsecured Credentials (4)
- Brute Force (3)
- Exploit Public-Facing Application (3)
- Command and Scripting Interpreter (2)
- Data from Information Repositories (2)
- External Remote Services (2)
- Server Software Component (2)
- Exfiltration Over Alternative Protocol (1)
- Phishing for Information (1)
- Process Injection (1)
- Trusted Relationship (1)
- Use Alternate Authentication Material (1)
Execution
55 detectors
- Command and Scripting Interpreter (16)
- User Execution (16)
- System Services (8)
- Scheduled Task/Job (6)
- Phishing (5)
- Remote Services (5)
- Windows Management Instrumentation (4)
- Create or Modify System Process (3)
- Native API (3)
- Boot or Logon Autostart Execution (2)
- Unsecured Credentials (2)
- Application Layer Protocol (1)
- Clipboard Data (1)
- Cloud Administration Command (1)
- Credentials from Password Stores (1)
- Deploy Container (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Masquerading (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- Serverless Execution (1)
- Steal Application Access Token (1)
- Taint Shared Content (1)
- Valid Accounts (1)
Persistence
55 detectors
- Account Manipulation (14)
- Boot or Logon Autostart Execution (12)
- Create or Modify System Process (7)
- Scheduled Task/Job (7)
- Valid Accounts (6)
- Event Triggered Execution (4)
- Masquerading (3)
- Server Software Component (3)
- Create Account (2)
- External Remote Services (2)
- System Services (2)
- Boot or Logon Initialization Scripts (1)
- Browser Extensions (1)
- Command and Scripting Interpreter (1)
- Domain or Tenant Policy Modification (1)
- Hide Artifacts (1)
- Hijack Execution Flow (1)
- Modify Authentication Process (1)
- Pre-OS Boot (1)
- Remote Services (1)
- Software Extensions (1)
- User Execution (1)
Privilege Escalation
31 detectors
- Account Manipulation (8)
- Abuse Elevation Control Mechanism (6)
- Valid Accounts (6)
- Boot or Logon Autostart Execution (3)
- Create or Modify System Process (3)
- Scheduled Task/Job (3)
- Domain or Tenant Policy Modification (2)
- Event Triggered Execution (2)
- Access Token Manipulation (1)
- Boot or Logon Initialization Scripts (1)
- Escape to Host (1)
- Hijack Execution Flow (1)
- Process Injection (1)
- System Services (1)
Defense Evasion
76 detectors
- Impair Defenses (27)
- System Binary Proxy Execution (14)
- Process Injection (8)
- Masquerading (6)
- Phishing (5)
- Abuse Elevation Control Mechanism (4)
- Hide Artifacts (4)
- Indicator Removal (4)
- Hijack Execution Flow (3)
- Obfuscated Files or Information (3)
- Valid Accounts (3)
- Application Layer Protocol (2)
- Create or Modify System Process (2)
- Rootkit (2)
- Command and Scripting Interpreter (1)
- Credentials from Password Stores (1)
- Data Encrypted for Impact (1)
- Deobfuscate/Decode Files or Information (1)
- Domain or Tenant Policy Modification (1)
- Exploitation for Defense Evasion (1)
- Inhibit System Recovery (1)
- Modify Authentication Process (1)
- Modify Registry (1)
- OS Credential Dumping (1)
- Proxy (1)
- Reflective Code Loading (1)
- Remote Services (1)
- Rogue Domain Controller (1)
- Unsecured Credentials (1)
- User Execution (1)
Credential Access
69 detectors
- Unsecured Credentials (18)
- Brute Force (15)
- OS Credential Dumping (11)
- Steal or Forge Kerberos Tickets (7)
- Valid Accounts (7)
- Steal or Forge Authentication Certificates (6)
- Steal Application Access Token (5)
- Account Discovery (4)
- Credentials from Password Stores (4)
- Adversary-in-the-Middle (3)
- Compromise Accounts (3)
- Modify Authentication Process (3)
- Command and Scripting Interpreter (2)
- Forced Authentication (2)
- Forge Web Credentials (2)
- Input Capture (2)
- Use Alternate Authentication Material (2)
- Defacement (1)
- Deobfuscate/Decode Files or Information (1)
- Exploitation of Remote Services (1)
- Multi-Factor Authentication Request Generation (1)
- Network Sniffing (1)
- Rogue Domain Controller (1)
- System Service Discovery (1)
- Windows Management Instrumentation (1)
Discovery
28 detectors
- Account Discovery (8)
- System Network Configuration Discovery (5)
- Network Service Discovery (4)
- Remote System Discovery (4)
- System Information Discovery (3)
- System Service Discovery (3)
- File and Directory Discovery (2)
- Steal or Forge Authentication Certificates (2)
- Automated Collection (1)
- Browser Information Discovery (1)
- Brute Force (1)
- Cloud Service Discovery (1)
- Container and Resource Discovery (1)
- Data from Local System (1)
- Network Share Discovery (1)
- Network Sniffing (1)
- OS Credential Dumping (1)
- Steal or Forge Kerberos Tickets (1)
Lateral Movement
30 detectors
- Remote Services (24)
- Use Alternate Authentication Material (4)
- System Services (3)
- Remote Access Tools (2)
- Adversary-in-the-Middle (1)
- Command and Scripting Interpreter (1)
- Exploitation of Remote Services (1)
- Forge Web Credentials (1)
- Impair Defenses (1)
- Scheduled Task/Job (1)
- Steal Application Access Token (1)
- Taint Shared Content (1)
- Unsecured Credentials (1)
- User Execution (1)
- Valid Accounts (1)
- Windows Management Instrumentation (1)
Collection
21 detectors
- Automated Exfiltration (5)
- Data from Cloud Storage (4)
- Data from Local System (4)
- Archive Collected Data (3)
- Data Staged (3)
- Email Collection (3)
- Audio Capture (2)
- Data from Information Repositories (2)
- Valid Accounts (2)
- Automated Collection (1)
- Browser Information Discovery (1)
- Clipboard Data (1)
- Command and Scripting Interpreter (1)
- Exfiltration Over Physical Medium (1)
- Gather Victim Host Information (1)
- Input Capture (1)
- Screen Capture (1)
- Video Capture (1)
Command and Control
32 detectors
- Application Layer Protocol (17)
- Protocol Tunneling (3)
- Remote Access Tools (3)
- Web Service (3)
- Exfiltration Over Web Service (2)
- Ingress Tool Transfer (2)
- Non-Application Layer Protocol (2)
- Non-Standard Port (2)
- Remote Services (2)
- System Binary Proxy Execution (2)
- Command and Scripting Interpreter (1)
- Dynamic Resolution (1)
- Exfiltration Over Alternative Protocol (1)
- Impair Defenses (1)
- Proxy (1)
Exfiltration
21 detectors
- Exfiltration Over Alternative Protocol (7)
- Automated Exfiltration (6)
- Transfer Data to Cloud Account (4)
- Data from Cloud Storage (3)
- Email Collection (2)
- Exfiltration Over Web Service (2)
- Web Service (2)
- Application Layer Protocol (1)
- Command and Scripting Interpreter (1)
- Data Staged (1)
- Exfiltration Over C2 Channel (1)
- Exfiltration Over Physical Medium (1)
- Phishing (1)
Impact
22 detectors
- Data Manipulation (6)
- Account Access Removal (4)
- Inhibit System Recovery (4)
- Endpoint Denial of Service (2)
- Network Denial of Service (2)
- Resource Hijacking (2)
- Data Destruction (1)
- Data Encrypted for Impact (1)
- Defacement (1)
- Financial Theft (1)
- Input Capture (1)
- Obfuscated Files or Information (1)
- Rootkit (1)
- Service Stop (1)