Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
81 detectors match the current filters.
Download CSV12 tactics · 52 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
5 detectors
Execution
12 detectors
Persistence
18 detectors
- Boot or Logon Autostart Execution (6)
- Account Manipulation (4)
- Valid Accounts (4)
- Hijack Execution Flow (3)
- Server Software Component (2)
- BITS Jobs (1)
- Create Account (1)
- Escape to Host (1)
- Event Triggered Execution (1)
- External Remote Services (1)
- Hide Artifacts (1)
- Replication Through Removable Media (1)
Privilege Escalation
13 detectors
Defense Evasion
21 detectors
- System Binary Proxy Execution (5)
- Obfuscated Files or Information (3)
- User Execution (3)
- Hide Artifacts (2)
- Impair Defenses (2)
- Masquerading (2)
- Process Injection (2)
- Create Account (1)
- Data Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Domain or Tenant Policy Modification (1)
- Hijack Execution Flow (1)
- Indirect Command Execution (1)
- Ingress Tool Transfer (1)
- Modify Authentication Process (1)
- OS Credential Dumping (1)
- Trusted Developer Utilities Proxy Execution (1)
- Valid Accounts (1)
Credential Access
7 detectors
Discovery
6 detectors
Lateral Movement
5 detectors
Collection
5 detectors
Command and Control
3 detectors
Exfiltration
5 detectors