Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A contained executable from a mounted share initiated a suspicious outbound network connection Medium 1 variation

    A contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Escape to Host (T1611)
    Required data: XDR Agent
    Attacker's goals: Gain high privileged command execution on the host machine via one of its running containers.
    Investigative actions: Check if the requested IP address is known or malicious. Investigate the contained process and its process tree.

    Variations

    A contained executable from a mounted share initiated a suspicious outbound network connection

    Medium overridden

    A cloud machine contained executable from a mounted share initiated a suspicious outbound network connection. Running binaries from a mounted share is highly dangerous and not typical. overridden