Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
164 detectors match the current filters. technique: T1078 ✕
Download CSV13 tactics · 32 techniques · cell shade = number of matching detectors; click a cell to list them.
Resource Development
2 detectors
Initial Access
91 detectors
- Valid Accounts (91)
- Unsecured Credentials (7)
- Steal Application Access Token (6)
- Brute Force (5)
- Proxy (5)
- Trusted Relationship (5)
- Account Manipulation (4)
- Resource Hijacking (3)
- Abuse Elevation Control Mechanism (2)
- Cloud Service Discovery (2)
- Compromise Accounts (2)
- Data from Information Repositories (2)
- Forge Web Credentials (2)
- Modify Authentication Process (2)
- Automated Collection (1)
- Automated Exfiltration (1)
- Cloud Service Dashboard (1)
- Command and Scripting Interpreter (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Phishing (1)
- Remote Services (1)
- Use Alternate Authentication Material (1)
Execution
2 detectors
Persistence
52 detectors
- Valid Accounts (52)
- Account Manipulation (28)
- Steal or Forge Authentication Certificates (2)
- Account Access Removal (1)
- Create Account (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- Forge Web Credentials (1)
- Hide Artifacts (1)
- Masquerading (1)
- Multi-Factor Authentication Request Generation (1)
- Remote Services (1)
- Trusted Relationship (1)
- Unsecured Credentials (1)
Privilege Escalation
47 detectors
- Valid Accounts (47)
- Account Manipulation (21)
- Abuse Elevation Control Mechanism (5)
- Steal or Forge Authentication Certificates (2)
- Trusted Relationship (2)
- Unsecured Credentials (2)
- Use Alternate Authentication Material (2)
- Account Discovery (1)
- Data Destruction (1)
- Domain or Tenant Policy Modification (1)
- System Services (1)
Defense Evasion
16 detectors
Credential Access
18 detectors
- Valid Accounts (18)
- Unsecured Credentials (10)
- Steal Application Access Token (6)
- Brute Force (5)
- Account Manipulation (3)
- Forge Web Credentials (2)
- Steal or Forge Authentication Certificates (2)
- Command and Scripting Interpreter (1)
- Modify Authentication Process (1)
- Multi-Factor Authentication Request Generation (1)
- OS Credential Dumping (1)
- Trusted Relationship (1)
- Use Alternate Authentication Material (1)
Discovery
3 detectors
Lateral Movement
4 detectors
Collection
3 detectors
Command and Control
5 detectors
Exfiltration
1 detector
Impact
6 detectors