Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
65 detectors match the current filters. technique: T1552 ✕
Download CSV9 tactics · 16 techniques · cell shade = number of matching detectors; click a cell to list them.
Initial Access
9 detectors
Execution
2 detectors
Persistence
1 detector
Privilege Escalation
2 detectors
Defense Evasion
1 detector
Credential Access
65 detectors
- Unsecured Credentials (65)
- Steal Application Access Token (10)
- Valid Accounts (10)
- Credentials from Password Stores (4)
- Data from Cloud Storage (3)
- OS Credential Dumping (3)
- Exploit Public-Facing Application (2)
- Steal or Forge Authentication Certificates (2)
- Account Discovery (1)
- Brute Force (1)
- Command and Scripting Interpreter (1)
- Deobfuscate/Decode Files or Information (1)
- Forge Web Credentials (1)
- Modify Authentication Process (1)
- Use Alternate Authentication Material (1)
- Windows Management Instrumentation (1)
Discovery
1 detector
Lateral Movement
1 detector
Collection
3 detectors