Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
91 detectors match the current filters. tactic: TA0008 ✕
Download CSV9 tactics · 31 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
3 detectors
Execution
16 detectors
Persistence
7 detectors
Privilege Escalation
2 detectors
Defense Evasion
3 detectors
Credential Access
9 detectors
- Use Alternate Authentication Material (7)
- Adversary-in-the-Middle (4)
- Forge Web Credentials (2)
- Account Manipulation (1)
- Brute Force (1)
- Exploitation of Remote Services (1)
- Remote Services (1)
- Steal Application Access Token (1)
- Steal or Forge Kerberos Tickets (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Discovery
2 detectors
Lateral Movement
91 detectors
- Remote Services (63)
- Use Alternate Authentication Material (19)
- System Services (8)
- Adversary-in-the-Middle (4)
- Valid Accounts (4)
- Account Manipulation (3)
- Cloud Administration Command (3)
- Command and Scripting Interpreter (3)
- Exploitation of Remote Services (3)
- Forge Web Credentials (2)
- Impair Defenses (2)
- Internal Spearphishing (2)
- Lateral Tool Transfer (2)
- Remote Access Tools (2)
- Scheduled Task/Job (2)
- Windows Management Instrumentation (2)
- Brute Force (1)
- Cloud Service Discovery (1)
- Create or Modify System Process (1)
- Exploit Public-Facing Application (1)
- Hijack Execution Flow (1)
- Modify Cloud Compute Infrastructure (1)
- Network Boundary Bridging (1)
- Network Service Discovery (1)
- Remote Service Session Hijacking (1)
- Replication Through Removable Media (1)
- Steal Application Access Token (1)
- Steal or Forge Kerberos Tickets (1)
- Taint Shared Content (1)
- Unsecured Credentials (1)
- User Execution (1)
Command and Control
2 detectors