Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1489 ✕

Download CSV Show ATT&CK heatmap
  • A service was disabled Informational 3 variations

    A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Impact (TA0040)
    ATT&CK techniques: Service Stop (T1489)
    Required data: XDR Agent
    Attacker's goals: Evade detection by certain programs. Limit the functionality and availability of systems, services, and network resources.
    Investigative actions: Check if the disabled service could potentially threaten a malicious actor, or if holds a critical role. Investigate the disabling process to understand if it performed other suspicious actions.

    Variations

    A service was disabled without using the ServiceControlManager RPC interface

    Informational overridden

    A service was disabled abnormally through the registry. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden

    An injected process performed an uncommon service deactivation

    Informational overridden

    A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden

    An unsigned process performed an uncommon service deactivation

    Low overridden

    A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden