Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1036 ✕

Download CSV Show ATT&CK heatmap
  • A process is masquerading as a common Microsoft product Informational 5 variations

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Defense Evasion (TA0005)
    ATT&CK techniques: Masquerading (T1036)
    Required data: XDR Agent
    Detector tags: EDR Windows Disguised Processes
    Attacker's goals: An attacker is attempting to masquerade as a Microsoft software image to execute malicious code.
    Investigative actions: Investigate the executed process image and check if it is malicious. Investigate the actor process that executed the process and check if it is malicious.

    Variations

    An unsigned actor executed masqueraded process which was downloaded from unexpected source

    High overridden

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden

    An unsigned and rare actor executing masqueraded process with uncommon characteristics

    High overridden

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden

    A process that was executed by remote causality actor is masquerading as a common Microsoft product

    Medium overridden

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden

    A process is masquerading as a common Microsoft Lolbin

    Low overridden

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden

    A process running from a commonly abused directory is masquerading as a common Microsoft product

    Low overridden

    An attacker might leverage common Microsoft software image names to run malicious processes without being caught. overridden