Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
16 detectors match the current filters. technique: T1020 ✕
Download CSVSeverity mix
- Informational 8 50%
- Low 6 38%
- Medium 2 13%
Detector type
- Analytics 4 25%
- Analytics BIOC 11 69%
- BIOC 1 6%
Data sources
-
AzureAD 1
Detector tags
What each module brings
See the ATT&CK matrix for this selection →Detectors this selection gains from each licensable module, how much of ATT&CK they cover, and how their severities split. Click a module to keep only its detectors.
| Module | Licensed by | Detectors | Tactics covered | Severity mix |
|---|---|---|---|---|
| Cortex Cloud | Cloud Runtime Security (CRS) | 8 | 2 |
5 informational · 3 low
|
| Identity Threat Detection (ITDR) | Identity Threat Detection (ITDR) | 6 | 5 |
3 informational · 2 low · 1 medium
|
| Email Security | Email Security | 3 | 2 |
1 informational · 2 low
|
| Platform Analytics | Included with the platform | 2 | 2 |
1 low · 1 medium
|