Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
139 detectors match the current filters. tactic: TA0006 ✕
Download CSV10 tactics · 33 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
6 detectors
Initial Access
11 detectors
- Valid Accounts (10)
- Steal Application Access Token (7)
- Unsecured Credentials (7)
- Brute Force (2)
- Forge Web Credentials (2)
- Trusted Relationship (2)
- Account Manipulation (1)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Phishing (1)
- Use Alternate Authentication Material (1)
Execution
14 detectors
Persistence
10 detectors
Privilege Escalation
1 detector
Defense Evasion
6 detectors
Credential Access
139 detectors
- Unsecured Credentials (47)
- Brute Force (20)
- OS Credential Dumping (20)
- Credentials from Password Stores (15)
- Steal Application Access Token (13)
- Valid Accounts (12)
- Steal or Forge Authentication Certificates (11)
- User Execution (10)
- Modify Authentication Process (9)
- Compromise Accounts (6)
- Forge Web Credentials (6)
- Account Discovery (5)
- Adversary-in-the-Middle (5)
- Forced Authentication (5)
- Account Manipulation (4)
- Steal or Forge Kerberos Tickets (4)
- Command and Scripting Interpreter (3)
- File and Directory Discovery (3)
- Network Sniffing (3)
- Cloud Service Discovery (2)
- Input Capture (2)
- Multi-Factor Authentication Request Generation (2)
- Rogue Domain Controller (2)
- System Service Discovery (2)
- Trusted Relationship (2)
- Use Alternate Authentication Material (2)
- Exploitation of Remote Services (1)
- Hide Artifacts (1)
- Phishing (1)
- Steal Web Session Cookie (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Windows Management Instrumentation (1)
Discovery
13 detectors
- Account Discovery (5)
- Steal or Forge Authentication Certificates (4)
- Credentials from Password Stores (3)
- File and Directory Discovery (3)
- Network Sniffing (3)
- OS Credential Dumping (3)
- Cloud Service Discovery (2)
- System Service Discovery (2)
- Steal or Forge Kerberos Tickets (1)
- System Information Discovery (1)
- System Owner/User Discovery (1)
- Unsecured Credentials (1)
Lateral Movement
3 detectors
Collection
2 detectors