Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
63 detectors match the current filters. tactic: TA0006 ✕
Download CSV10 tactics · 20 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
10 detectors
Initial Access
6 detectors
Execution
2 detectors
Persistence
1 detector
Privilege Escalation
3 detectors
Defense Evasion
1 detector
Credential Access
63 detectors
- Brute Force (34)
- Compromise Accounts (10)
- Unsecured Credentials (10)
- Steal or Forge Kerberos Tickets (8)
- Valid Accounts (6)
- Adversary-in-the-Middle (5)
- Credentials from Password Stores (4)
- Use Alternate Authentication Material (4)
- Data from Cloud Storage (3)
- Account Discovery (2)
- Exploit Public-Facing Application (2)
- Steal Application Access Token (2)
- User Execution (2)
- Account Manipulation (1)
- Deobfuscate/Decode Files or Information (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Phishing (1)
- Remote Services (1)
- Steal or Forge Authentication Certificates (1)
Discovery
2 detectors
Lateral Movement
5 detectors
Collection
3 detectors