Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
153 detectors match the current filters. tactic: TA0004 ✕
Download CSV9 tactics · 27 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
7 detectors
Execution
13 detectors
- Escape to Host (6)
- Deploy Container (5)
- Scheduled Task/Job (3)
- System Services (2)
- Access Token Manipulation (1)
- Account Manipulation (1)
- Command and Scripting Interpreter (1)
- Container Administration Command (1)
- Create or Modify System Process (1)
- Hijack Execution Flow (1)
- User Execution (1)
- Valid Accounts (1)
Persistence
68 detectors
- Account Manipulation (47)
- Valid Accounts (22)
- Hijack Execution Flow (6)
- Boot or Logon Autostart Execution (4)
- Event Triggered Execution (4)
- Create or Modify System Process (2)
- Domain or Tenant Policy Modification (2)
- Scheduled Task/Job (2)
- Steal or Forge Authentication Certificates (2)
- Access Token Manipulation (1)
- Boot or Logon Initialization Scripts (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Escape to Host (1)
Privilege Escalation
153 detectors
- Account Manipulation (54)
- Valid Accounts (47)
- Abuse Elevation Control Mechanism (27)
- Escape to Host (13)
- Hijack Execution Flow (8)
- Domain or Tenant Policy Modification (7)
- Boot or Logon Autostart Execution (6)
- Deploy Container (5)
- Event Triggered Execution (5)
- Access Token Manipulation (4)
- Create or Modify System Process (3)
- Exploitation for Privilege Escalation (3)
- Scheduled Task/Job (3)
- Account Discovery (2)
- Process Injection (2)
- Steal or Forge Authentication Certificates (2)
- System Services (2)
- Trusted Relationship (2)
- Unsecured Credentials (2)
- Use Alternate Authentication Material (2)
- Boot or Logon Initialization Scripts (1)
- Cloud Infrastructure Discovery (1)
- Command and Scripting Interpreter (1)
- Container Administration Command (1)
- Container and Resource Discovery (1)
- Data Destruction (1)
- User Execution (1)
Defense Evasion
17 detectors
Credential Access
4 detectors
Discovery
4 detectors
Lateral Movement
2 detectors
Impact
1 detector