Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapA commonly abused process connected to a rare external host Low 3 variations
A commonly abused process connected to a rare external host.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Command and Control (TA0011)ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)Required data: XDR AgentDetector tags: EDR Windows C2 AnalyticsAttacker's goals: Communicate with the attacker's Command and Control (C2) infrastructure.Investigative actions: Investigate the actor process connected to the external host. Get further details about the uncommon external destination. Assess whether this communication pattern is expected or not.Variations
A commonly abused renamed process connected to a rare external host
Medium overridden
A commonly abused renamed process connected to a rare external host. overridden
A commonly abused process connected to a globally rare external host
Low overridden
A commonly abused process connected to a globally rare external host. overridden
A commonly abused rare process connected to a rare external host
Low overridden
A commonly abused rare process connected to a rare external host. overridden