Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
55 detectors match the current filters. tactic: TA0002 ✕
Download CSV10 tactics · 25 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
7 detectors
Execution
55 detectors
- Command and Scripting Interpreter (16)
- User Execution (16)
- System Services (8)
- Scheduled Task/Job (6)
- Phishing (5)
- Remote Services (5)
- Windows Management Instrumentation (4)
- Create or Modify System Process (3)
- Native API (3)
- Boot or Logon Autostart Execution (2)
- Unsecured Credentials (2)
- Application Layer Protocol (1)
- Clipboard Data (1)
- Cloud Administration Command (1)
- Credentials from Password Stores (1)
- Deploy Container (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Masquerading (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- Serverless Execution (1)
- Steal Application Access Token (1)
- Taint Shared Content (1)
- Valid Accounts (1)
Persistence
7 detectors
Privilege Escalation
4 detectors
Defense Evasion
2 detectors
Credential Access
3 detectors
Lateral Movement
6 detectors
Collection
1 detector
Command and Control
1 detector
Exfiltration
1 detector