Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
161 detectors match the current filters.
Download CSV12 tactics · 77 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
8 detectors
Execution
21 detectors
- Command and Scripting Interpreter (9)
- User Execution (7)
- Container and Resource Discovery (2)
- Deploy Container (2)
- Automated Exfiltration (1)
- Cloud Administration Command (1)
- Credentials from Password Stores (1)
- Exploitation for Client Execution (1)
- Hijack Execution Flow (1)
- Masquerading (1)
- Remote Services (1)
- System Binary Proxy Execution (1)
- System Services (1)
Persistence
28 detectors
- Boot or Logon Autostart Execution (8)
- Account Manipulation (6)
- Valid Accounts (4)
- Hijack Execution Flow (3)
- BITS Jobs (2)
- Event Triggered Execution (2)
- Server Software Component (2)
- Boot or Logon Initialization Scripts (1)
- Create Account (1)
- Create or Modify System Process (1)
- Escape to Host (1)
- External Remote Services (1)
- Hide Artifacts (1)
- Process Injection (1)
- Remote Services (1)
- Replication Through Removable Media (1)
- Scheduled Task/Job (1)
- Software Extensions (1)
Privilege Escalation
26 detectors
- Abuse Elevation Control Mechanism (8)
- Valid Accounts (7)
- Account Manipulation (4)
- Escape to Host (3)
- Boot or Logon Autostart Execution (2)
- Exploitation for Privilege Escalation (2)
- Hijack Execution Flow (2)
- Access Token Manipulation (1)
- Event Triggered Execution (1)
- Process Injection (1)
- User Execution (1)
Defense Evasion
36 detectors
- System Binary Proxy Execution (9)
- Impair Defenses (5)
- Obfuscated Files or Information (4)
- Indicator Removal (3)
- Process Injection (3)
- User Execution (3)
- Access Token Manipulation (2)
- Hide Artifacts (2)
- Masquerading (2)
- Trusted Developer Utilities Proxy Execution (2)
- Create Account (1)
- Data Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Domain or Tenant Policy Modification (1)
- Hijack Execution Flow (1)
- Indirect Command Execution (1)
- Ingress Tool Transfer (1)
- Modify Authentication Process (1)
- OS Credential Dumping (1)
- Scheduled Task/Job (1)
- System Script Proxy Execution (1)
- Valid Accounts (1)
Credential Access
21 detectors
- OS Credential Dumping (12)
- Unsecured Credentials (3)
- Steal or Forge Kerberos Tickets (2)
- Adversary-in-the-Middle (1)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Credentials from Password Stores (1)
- Exploit Public-Facing Application (1)
- Hide Artifacts (1)
- Input Capture (1)
- Network Service Discovery (1)
Discovery
16 detectors
- Account Discovery (3)
- Network Service Discovery (3)
- Remote System Discovery (3)
- Cloud Service Discovery (2)
- Container and Resource Discovery (2)
- Deploy Container (2)
- Browser Information Discovery (1)
- Brute Force (1)
- File and Directory Discovery (1)
- Permission Groups Discovery (1)
- Resource Hijacking (1)
- System Network Configuration Discovery (1)
- System Service Discovery (1)
Lateral Movement
8 detectors
Collection
5 detectors
Command and Control
6 detectors
Exfiltration
6 detectors