Detectors
Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.
64 detectors match the current filters. technique: T1204 ✕
Download CSVSeverity mix
- Informational 39 61%
- Low 16 25%
- Medium 7 11%
- High 2 3%
Detector type
- Analytics 13 20%
- Analytics BIOC 43 67%
- BIOC 7 11%
- Correlation Rule 1 2%
Data sources
Showing the top 10 of 14; the filter rail lists them all.
Detector tags
Showing the top 10 of 15; the filter rail lists them all.
What each module brings
See the ATT&CK matrix for this selection →Detectors this selection gains from each licensable module, how much of ATT&CK they cover, and how their severities split. Click a module to keep only its detectors.
| Module | Licensed by | Detectors | Tactics covered | Severity mix |
|---|---|---|---|---|
| Platform Analytics | Included with the platform | 30 | 6 |
12 informational · 11 low · 6 medium · 1 high
|
| Email Security | Email Security | 22 | 4 |
20 informational · 2 low
|
| Identity Analytics | Included with the platform | 5 | 1 |
4 informational · 1 low
|
| Cortex Cloud | Cloud Runtime Security (CRS) | 5 | 1 |
2 informational · 1 low · 1 medium · 1 high
|
| Identity Threat Detection (ITDR) | Identity Threat Detection (ITDR) | 2 | 4 |
1 informational · 1 low
|