Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
68 detectors match the current filters. technique: T1059 ✕
Download CSV10 tactics · 21 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
2 detectors
Execution
68 detectors
- Command and Scripting Interpreter (68)
- Remote Services (3)
- Account Manipulation (2)
- Automated Exfiltration (2)
- Cloud Administration Command (2)
- Credentials from Password Stores (2)
- Data from Local System (2)
- Impair Defenses (2)
- Access Token Manipulation (1)
- Application Layer Protocol (1)
- Boot or Logon Autostart Execution (1)
- Clipboard Data (1)
- Deobfuscate/Decode Files or Information (1)
- Event Triggered Execution (1)
- Exfiltration Over C2 Channel (1)
- Exploit Public-Facing Application (1)
- Obfuscated Files or Information (1)
- Screen Capture (1)
- Steal Application Access Token (1)
- Unsecured Credentials (1)
- Valid Accounts (1)
Persistence
4 detectors
Privilege Escalation
1 detector
Defense Evasion
4 detectors
Credential Access
3 detectors
Lateral Movement
3 detectors
Collection
3 detectors
Command and Control
1 detector