Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
145 detectors match the current filters. tactic: TA0002 ✕
Download CSV11 tactics · 43 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
11 detectors
Execution
145 detectors
- Command and Scripting Interpreter (46)
- User Execution (43)
- Deploy Container (15)
- System Services (14)
- Remote Services (11)
- Brute Force (10)
- Phishing (9)
- Windows Management Instrumentation (8)
- Scheduled Task/Job (7)
- Escape to Host (6)
- Masquerading (6)
- Cloud Administration Command (5)
- Container Administration Command (5)
- Serverless Execution (4)
- Create or Modify System Process (3)
- Account Manipulation (2)
- Automated Exfiltration (2)
- Boot or Logon Autostart Execution (2)
- Container and Resource Discovery (2)
- Credentials from Password Stores (2)
- Data from Local System (2)
- Event Triggered Execution (2)
- Impair Defenses (2)
- Native API (2)
- Unsecured Credentials (2)
- Valid Accounts (2)
- Access Token Manipulation (1)
- Account Discovery (1)
- Application Layer Protocol (1)
- Clipboard Data (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Hide Artifacts (1)
- Hijack Execution Flow (1)
- Impersonation (1)
- Lateral Tool Transfer (1)
- Obfuscated Files or Information (1)
- Remote System Discovery (1)
- Screen Capture (1)
- Steal Application Access Token (1)
- System Binary Proxy Execution (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
Persistence
13 detectors
- Scheduled Task/Job (5)
- Command and Scripting Interpreter (4)
- Account Manipulation (2)
- Boot or Logon Autostart Execution (2)
- Create or Modify System Process (2)
- Event Triggered Execution (2)
- System Services (2)
- Access Token Manipulation (1)
- Automated Exfiltration (1)
- Cloud Administration Command (1)
- Impair Defenses (1)
- Serverless Execution (1)
- User Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
13 detectors
- Escape to Host (6)
- Deploy Container (5)
- Scheduled Task/Job (3)
- System Services (2)
- Access Token Manipulation (1)
- Account Manipulation (1)
- Command and Scripting Interpreter (1)
- Container Administration Command (1)
- Create or Modify System Process (1)
- Hijack Execution Flow (1)
- User Execution (1)
- Valid Accounts (1)
Defense Evasion
13 detectors
Credential Access
14 detectors
Discovery
5 detectors
Lateral Movement
11 detectors
Collection
3 detectors
Command and Control
1 detector