Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1106 ✕
Download CSV Show ATT&CK heatmapA suspicious direct syscall was executed Low 2 variations
A suspicious direct syscall was executed.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: Native API (T1106)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Direct Syscall AnalyticsAttacker's goals: An attacker might try to use direct syscalls to evade detection from a legitimate program.Investigative actions: Investigate the direct syscall-mapped image to verify if it is malicious. Check if this direct syscall is part of the process execution flow.Variations
A suspicious direct syscall was executed by unsigned process from a user folder
High overridden
A suspicious direct syscall was executed by unsigned process from a user folder. overridden
A suspicious direct syscall was executed by a DLL host application
Medium overridden
A suspicious direct syscall was executed by a DLL host application. overridden