Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
251 detectors match the current filters. tactic: TA0006 ✕
Download CSV11 tactics · 41 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
16 detectors
Initial Access
17 detectors
- Valid Accounts (13)
- Unsecured Credentials (9)
- Steal Application Access Token (8)
- Brute Force (5)
- Exploit Public-Facing Application (2)
- Forge Web Credentials (2)
- Phishing (2)
- Trusted Relationship (2)
- Account Manipulation (1)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Use Alternate Authentication Material (1)
- User Execution (1)
Execution
16 detectors
Persistence
11 detectors
Privilege Escalation
4 detectors
Defense Evasion
7 detectors
Credential Access
251 detectors
- Unsecured Credentials (65)
- Brute Force (56)
- OS Credential Dumping (43)
- Credentials from Password Stores (28)
- Valid Accounts (18)
- Compromise Accounts (16)
- Steal Application Access Token (15)
- Steal or Forge Kerberos Tickets (13)
- Steal or Forge Authentication Certificates (12)
- User Execution (12)
- Modify Authentication Process (11)
- Adversary-in-the-Middle (10)
- Account Discovery (7)
- Use Alternate Authentication Material (7)
- Forge Web Credentials (6)
- Input Capture (6)
- Account Manipulation (5)
- Forced Authentication (5)
- Network Sniffing (4)
- Command and Scripting Interpreter (3)
- Data from Cloud Storage (3)
- File and Directory Discovery (3)
- Multi-Factor Authentication Request Generation (3)
- Automated Collection (2)
- Cloud Service Discovery (2)
- Exploit Public-Facing Application (2)
- Phishing (2)
- Rogue Domain Controller (2)
- System Service Discovery (2)
- Trusted Relationship (2)
- Defacement (1)
- Deobfuscate/Decode Files or Information (1)
- Exploitation of Remote Services (1)
- Hide Artifacts (1)
- Inhibit System Recovery (1)
- Network Service Discovery (1)
- Remote Services (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Windows Management Instrumentation (1)
Discovery
17 detectors
- Account Discovery (7)
- Network Sniffing (4)
- Steal or Forge Authentication Certificates (4)
- Brute Force (3)
- Credentials from Password Stores (3)
- File and Directory Discovery (3)
- OS Credential Dumping (3)
- Cloud Service Discovery (2)
- System Service Discovery (2)
- Network Service Discovery (1)
- Steal or Forge Kerberos Tickets (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
9 detectors
- Use Alternate Authentication Material (7)
- Adversary-in-the-Middle (4)
- Forge Web Credentials (2)
- Account Manipulation (1)
- Brute Force (1)
- Exploitation of Remote Services (1)
- Remote Services (1)
- Steal Application Access Token (1)
- Steal or Forge Kerberos Tickets (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Collection
9 detectors
Impact
2 detectors