Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
109 detectors match the current filters. tactic: TA0005 ✕
Download CSV6 tactics · 24 techniques · cell shade = number of matching detectors; click a cell to list them.
Execution
2 detectors
Privilege Escalation
1 detector
Defense Evasion
109 detectors
- Impair Defenses (27)
- System Binary Proxy Execution (18)
- Indicator Removal (15)
- Hide Artifacts (8)
- Masquerading (7)
- Process Injection (4)
- Subvert Trust Controls (4)
- Trusted Developer Utilities Proxy Execution (4)
- Deobfuscate/Decode Files or Information (3)
- File and Directory Permissions Modification (3)
- Obfuscated Files or Information (3)
- Rootkit (3)
- System Script Proxy Execution (3)
- Virtualization/Sandbox Evasion (3)
- Access Token Manipulation (2)
- Hijack Execution Flow (2)
- Indirect Command Execution (2)
- Inhibit System Recovery (2)
- BITS Jobs (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Exfiltration Over Alternative Protocol (1)
- Valid Accounts (1)
- Windows Management Instrumentation (1)
Discovery
1 detector
Exfiltration
1 detector
Impact
3 detectors