Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1071 ✕

Download CSV Show ATT&CK heatmap
  • A commonly abused process connected to a rare external host Low 3 variations

    A commonly abused process connected to a rare external host.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Application Layer Protocol: Web Protocols (T1071.001)
    Required data: XDR Agent
    Detector tags: EDR Windows C2 Analytics
    Attacker's goals: Communicate with the attacker's Command and Control (C2) infrastructure.
    Investigative actions: Investigate the actor process connected to the external host. Get further details about the uncommon external destination. Assess whether this communication pattern is expected or not.

    Variations

    A commonly abused renamed process connected to a rare external host

    Medium overridden

    A commonly abused renamed process connected to a rare external host. overridden

    A commonly abused process connected to a globally rare external host

    Low overridden

    A commonly abused process connected to a globally rare external host. overridden

    A commonly abused rare process connected to a rare external host

    Low overridden

    A commonly abused rare process connected to a rare external host. overridden