Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
36 detectors match the current filters. tactic: TA0005 ✕
Download CSV8 tactics · 22 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
1 detector
Execution
3 detectors
Persistence
2 detectors
Privilege Escalation
3 detectors
Defense Evasion
36 detectors
- System Binary Proxy Execution (9)
- Impair Defenses (5)
- Obfuscated Files or Information (4)
- Indicator Removal (3)
- Process Injection (3)
- User Execution (3)
- Access Token Manipulation (2)
- Hide Artifacts (2)
- Masquerading (2)
- Trusted Developer Utilities Proxy Execution (2)
- Create Account (1)
- Data Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Domain or Tenant Policy Modification (1)
- Hijack Execution Flow (1)
- Indirect Command Execution (1)
- Ingress Tool Transfer (1)
- Modify Authentication Process (1)
- OS Credential Dumping (1)
- Scheduled Task/Job (1)
- System Script Proxy Execution (1)
- Valid Accounts (1)
Credential Access
1 detector
Command and Control
1 detector
Impact
1 detector