Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
129 detectors match the current filters. tactic: TA0001 ✕
Download CSV14 tactics · 37 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
6 detectors
Resource Development
1 detector
Initial Access
129 detectors
- Valid Accounts (74)
- Phishing (35)
- Trusted Relationship (11)
- External Remote Services (9)
- User Execution (9)
- Steal Application Access Token (7)
- Unsecured Credentials (7)
- Phishing for Information (6)
- Proxy (5)
- Account Manipulation (4)
- Exfiltration Over Alternative Protocol (4)
- Exploit Public-Facing Application (4)
- Impair Defenses (4)
- Server Software Component (4)
- Modify Authentication Process (3)
- Abuse Elevation Control Mechanism (2)
- Brute Force (2)
- Command and Scripting Interpreter (2)
- Data from Information Repositories (2)
- Forge Web Credentials (2)
- Impersonation (2)
- Automated Collection (1)
- Automated Exfiltration (1)
- Cloud Service Discovery (1)
- Compromise Accounts (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- Exploitation of Remote Services (1)
- Hardware Additions (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Process Injection (1)
- Remote Services (1)
- Resource Hijacking (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
- Use Alternate Authentication Material (1)
Execution
11 detectors
Persistence
12 detectors
- Valid Accounts (7)
- Account Manipulation (4)
- External Remote Services (4)
- Server Software Component (4)
- Domain or Tenant Policy Modification (1)
- Forge Web Credentials (1)
- Multi-Factor Authentication Request Generation (1)
- Remote Services (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
- Trusted Relationship (1)
Privilege Escalation
7 detectors
Defense Evasion
12 detectors
Credential Access
11 detectors
- Valid Accounts (10)
- Steal Application Access Token (7)
- Unsecured Credentials (7)
- Brute Force (2)
- Forge Web Credentials (2)
- Trusted Relationship (2)
- Account Manipulation (1)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Phishing (1)
- Use Alternate Authentication Material (1)
Discovery
1 detector
Lateral Movement
3 detectors
Collection
3 detectors
Command and Control
5 detectors
Exfiltration
5 detectors
Impact
2 detectors