Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
92 detectors match the current filters. tactic: TA0009 ✕
Download CSV8 tactics · 27 techniques · cell shade = number of matching detectors; click a cell to list them.
Reconnaissance
1 detector
Initial Access
3 detectors
Execution
3 detectors
Defense Evasion
3 detectors
Credential Access
9 detectors
Discovery
1 detector
Collection
92 detectors
- Data Staged (21)
- Data from Cloud Storage (20)
- Email Collection (13)
- Archive Collected Data (12)
- Automated Exfiltration (12)
- Data from Information Repositories (11)
- Automated Collection (7)
- Data from Local System (7)
- Exfiltration Over Physical Medium (5)
- Input Capture (4)
- Screen Capture (4)
- Audio Capture (3)
- Command and Scripting Interpreter (3)
- Unsecured Credentials (3)
- Valid Accounts (3)
- Clipboard Data (2)
- Modify Cloud Compute Infrastructure (2)
- OS Credential Dumping (2)
- Transfer Data to Cloud Account (2)
- Browser Information Discovery (1)
- Credentials from Password Stores (1)
- Data from Network Shared Drive (1)
- Exfiltration Over Alternative Protocol (1)
- Exfiltration Over Web Service (1)
- Gather Victim Host Information (1)
- Indicator Removal (1)
- Video Capture (1)
Exfiltration
21 detectors