Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A user logged in from an abnormal country or ASN Informational Identity Analytics 1 variation

    A user logged in from an unusual country or ASN. This may indicate that the account was compromised.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
    ATT&CK techniques: Compromise Accounts (T1586) Brute Force: Password Guessing (T1110.001)
    Required data: XDR Agent
    Attacker's goals: Gain user-account credentials.
    Investigative actions: Check if the user is currently located in the aforementioned country. Check for any other suspicious activity related to the account. Check other ASNs and Countries that the user logged in from. Look for additional login attempts.

    Variations

    A service account successfully logged in from a new country or ASN

    Low overridden

    A service account successfully logged in to an internet facing server from an unusual country or ASN. This may indicate that the account was compromised. overridden