Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
264 detectors match the current filters. tactic: TA0003 ✕
Download CSV11 tactics · 49 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
13 detectors
- Valid Accounts (8)
- Account Manipulation (4)
- External Remote Services (4)
- Server Software Component (4)
- Domain or Tenant Policy Modification (1)
- Forge Web Credentials (1)
- Multi-Factor Authentication Request Generation (1)
- Remote Services (1)
- Software Extensions (1)
- Supply Chain Compromise (1)
- Trusted Relationship (1)
Execution
13 detectors
- Scheduled Task/Job (5)
- Command and Scripting Interpreter (4)
- Account Manipulation (2)
- Boot or Logon Autostart Execution (2)
- Create or Modify System Process (2)
- Event Triggered Execution (2)
- System Services (2)
- Access Token Manipulation (1)
- Automated Exfiltration (1)
- Cloud Administration Command (1)
- Impair Defenses (1)
- Serverless Execution (1)
- User Execution (1)
- Windows Management Instrumentation (1)
Persistence
264 detectors
- Account Manipulation (90)
- Valid Accounts (52)
- Boot or Logon Autostart Execution (36)
- Event Triggered Execution (21)
- Scheduled Task/Job (18)
- Create Account (15)
- Create or Modify System Process (14)
- Hijack Execution Flow (11)
- Server Software Component (9)
- External Remote Services (7)
- Modify Authentication Process (7)
- Software Extensions (7)
- Remote Services (5)
- Cloud Application Integration (4)
- Command and Scripting Interpreter (4)
- Use Alternate Authentication Material (4)
- BITS Jobs (3)
- Domain or Tenant Policy Modification (3)
- Impair Defenses (3)
- Masquerading (3)
- Boot or Logon Initialization Scripts (2)
- Forge Web Credentials (2)
- Hide Artifacts (2)
- Permission Groups Discovery (2)
- Pre-OS Boot (2)
- Process Injection (2)
- Steal or Forge Authentication Certificates (2)
- System Services (2)
- Access Token Manipulation (1)
- Account Access Removal (1)
- Account Discovery (1)
- Application Layer Protocol (1)
- Automated Exfiltration (1)
- Browser Extensions (1)
- Cloud Administration Command (1)
- Compromise Host Software Binary (1)
- Data Destruction (1)
- Escape to Host (1)
- Exfiltration Over Alternative Protocol (1)
- Multi-Factor Authentication Request Generation (1)
- Office Application Startup (1)
- Replication Through Removable Media (1)
- Serverless Execution (1)
- Supply Chain Compromise (1)
- System Binary Proxy Execution (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
- User Execution (1)
- Windows Management Instrumentation (1)
Privilege Escalation
68 detectors
- Account Manipulation (47)
- Valid Accounts (22)
- Hijack Execution Flow (6)
- Boot or Logon Autostart Execution (4)
- Event Triggered Execution (4)
- Create or Modify System Process (2)
- Domain or Tenant Policy Modification (2)
- Scheduled Task/Job (2)
- Steal or Forge Authentication Certificates (2)
- Access Token Manipulation (1)
- Boot or Logon Initialization Scripts (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Escape to Host (1)
Defense Evasion
22 detectors
- Hijack Execution Flow (6)
- Account Manipulation (4)
- Modify Authentication Process (4)
- Impair Defenses (3)
- Masquerading (3)
- Use Alternate Authentication Material (3)
- Create or Modify System Process (2)
- Hide Artifacts (2)
- Process Injection (2)
- Valid Accounts (2)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Create Account (1)
- Domain or Tenant Policy Modification (1)
- Scheduled Task/Job (1)
- System Binary Proxy Execution (1)
Credential Access
11 detectors
Discovery
3 detectors
Lateral Movement
7 detectors
Command and Control
1 detector
Exfiltration
2 detectors
Impact
2 detectors