Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
76 detectors match the current filters. tactic: TA0005 ✕
Download CSV9 tactics · 30 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
5 detectors
Execution
2 detectors
Persistence
5 detectors
Privilege Escalation
5 detectors
Defense Evasion
76 detectors
- Impair Defenses (27)
- System Binary Proxy Execution (14)
- Process Injection (8)
- Masquerading (6)
- Phishing (5)
- Abuse Elevation Control Mechanism (4)
- Hide Artifacts (4)
- Indicator Removal (4)
- Hijack Execution Flow (3)
- Obfuscated Files or Information (3)
- Valid Accounts (3)
- Application Layer Protocol (2)
- Create or Modify System Process (2)
- Rootkit (2)
- Command and Scripting Interpreter (1)
- Credentials from Password Stores (1)
- Data Encrypted for Impact (1)
- Deobfuscate/Decode Files or Information (1)
- Domain or Tenant Policy Modification (1)
- Exploitation for Defense Evasion (1)
- Inhibit System Recovery (1)
- Modify Authentication Process (1)
- Modify Registry (1)
- OS Credential Dumping (1)
- Proxy (1)
- Reflective Code Loading (1)
- Remote Services (1)
- Rogue Domain Controller (1)
- Unsecured Credentials (1)
- User Execution (1)
Credential Access
3 detectors
Lateral Movement
1 detector
Command and Control
3 detectors