Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
69 detectors match the current filters. tactic: TA0006 ✕
Download CSV10 tactics · 25 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
3 detectors
Initial Access
7 detectors
Execution
3 detectors
Persistence
1 detector
Defense Evasion
3 detectors
Credential Access
69 detectors
- Unsecured Credentials (18)
- Brute Force (15)
- OS Credential Dumping (11)
- Steal or Forge Kerberos Tickets (7)
- Valid Accounts (7)
- Steal or Forge Authentication Certificates (6)
- Steal Application Access Token (5)
- Account Discovery (4)
- Credentials from Password Stores (4)
- Adversary-in-the-Middle (3)
- Compromise Accounts (3)
- Modify Authentication Process (3)
- Command and Scripting Interpreter (2)
- Forced Authentication (2)
- Forge Web Credentials (2)
- Input Capture (2)
- Use Alternate Authentication Material (2)
- Defacement (1)
- Deobfuscate/Decode Files or Information (1)
- Exploitation of Remote Services (1)
- Multi-Factor Authentication Request Generation (1)
- Network Sniffing (1)
- Rogue Domain Controller (1)
- System Service Discovery (1)
- Windows Management Instrumentation (1)
Discovery
6 detectors
Lateral Movement
3 detectors
Collection
1 detector
Impact
1 detector