Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
1677 detectors match the current filters.
Download CSVSeverity mix
- Informational 1088 65%
- Low 382 23%
- Medium 161 10%
- High 46 3%
Detector type
- Analytics 239 14%
- Analytics BIOC 1061 63%
- BIOC 367 22%
- Correlation Rule 10 1%
Data sources
-
XDR Agent 431
-
AWS Audit Log 258
-
Azure Audit Log 185
-
Gcp Audit Log 153
Showing the top 10 of 40; the filter rail lists them all.
What each module brings
See the ATT&CK matrix for this selection →Detectors this selection gains from each licensable module, how much of ATT&CK they cover, and how their severities split. Click a module to keep only its detectors.
| Module | Licensed by | Detectors | Tactics covered | Severity mix |
|---|---|---|---|---|
| Platform Analytics | Included with the platform | 895 | 14 |
474 informational · 257 low · 130 medium · 34 high
|
| Cortex Cloud | Cloud Runtime Security (CRS) | 397 | 13 |
328 informational · 47 low · 14 medium · 8 high
|
| Identity Analytics | Included with the platform | 175 | 12 |
115 informational · 44 low · 13 medium · 3 high
|
| Identity Threat Detection (ITDR) | Identity Threat Detection (ITDR) | 153 | 13 |
120 informational · 29 low · 3 medium · 1 high
|
| Email Security | Email Security | 78 | 9 |
63 informational · 14 low · 1 medium
|
| Enterprise Runtime Security | Enterprise Runtime Security (ADV-EP) | 1 | 0 |
1 high
|