Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
366 detectors match the current filters. tactic: TA0005 ✕
Download CSV12 tactics · 63 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
12 detectors
Execution
15 detectors
- User Execution (10)
- Masquerading (6)
- Command and Scripting Interpreter (4)
- Impair Defenses (3)
- Account Manipulation (1)
- Cloud Administration Command (1)
- Deobfuscate/Decode Files or Information (1)
- Hide Artifacts (1)
- Hijack Execution Flow (1)
- Impersonation (1)
- Obfuscated Files or Information (1)
- Phishing (1)
- System Binary Proxy Execution (1)
- Windows Management Instrumentation (1)
Persistence
22 detectors
- Hijack Execution Flow (6)
- Account Manipulation (4)
- Modify Authentication Process (4)
- Impair Defenses (3)
- Masquerading (3)
- Use Alternate Authentication Material (3)
- Create or Modify System Process (2)
- Hide Artifacts (2)
- Process Injection (2)
- Valid Accounts (2)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Command and Scripting Interpreter (1)
- Compromise Host Software Binary (1)
- Create Account (1)
- Domain or Tenant Policy Modification (1)
- Scheduled Task/Job (1)
- System Binary Proxy Execution (1)
Privilege Escalation
17 detectors
Defense Evasion
366 detectors
- Impair Defenses (114)
- System Binary Proxy Execution (40)
- Masquerading (31)
- Indicator Removal (24)
- Hide Artifacts (22)
- Process Injection (19)
- Valid Accounts (16)
- Impersonation (13)
- Obfuscated Files or Information (13)
- Hijack Execution Flow (10)
- Modify Cloud Compute Infrastructure (10)
- User Execution (10)
- Abuse Elevation Control Mechanism (9)
- Modify Authentication Process (9)
- Deobfuscate/Decode Files or Information (7)
- Phishing (7)
- Virtualization/Sandbox Evasion (7)
- Domain or Tenant Policy Modification (5)
- File and Directory Permissions Modification (5)
- Rootkit (5)
- Subvert Trust Controls (5)
- Trusted Developer Utilities Proxy Execution (5)
- Account Manipulation (4)
- Command and Scripting Interpreter (4)
- Data Destruction (4)
- Access Token Manipulation (3)
- Application Layer Protocol (3)
- Indirect Command Execution (3)
- OS Credential Dumping (3)
- Remote Services (3)
- System Script Proxy Execution (3)
- Use Alternate Authentication Material (3)
- Create or Modify System Process (2)
- Data Encrypted for Impact (2)
- Data Manipulation (2)
- Data from Cloud Storage (2)
- Exfiltration Over Alternative Protocol (2)
- Inhibit System Recovery (2)
- Reflective Code Loading (2)
- Rogue Domain Controller (2)
- Transfer Data to Cloud Account (2)
- Trusted Relationship (2)
- Unused/Unsupported Cloud Regions (2)
- BITS Jobs (1)
- Cloud Administration Command (1)
- Cloud Application Integration (1)
- Cloud Infrastructure Discovery (1)
- Cloud Service Discovery (1)
- Compromise Host Software Binary (1)
- Create Account (1)
- Credentials from Password Stores (1)
- Email Collection (1)
- Exploitation for Defense Evasion (1)
- Ingress Tool Transfer (1)
- Modify Registry (1)
- Network Boundary Bridging (1)
- Proxy (1)
- Scheduled Task/Job (1)
- Service Stop (1)
- Unsecured Credentials (1)
- Weaken Encryption (1)
- Web Service (1)
- Windows Management Instrumentation (1)
Credential Access
7 detectors
Discovery
5 detectors
Lateral Movement
3 detectors
Collection
3 detectors
Command and Control
6 detectors
Exfiltration
4 detectors