Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • A user performed suspiciously massive file activity Informational Identity Threat Module 1 variation

    A user generated massive file activity by size or distinct file count.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Collection (TA0009)
    ATT&CK techniques: Automated Collection (T1119) Data Staged: Local Data Staging (T1074.001) Data Staged: Remote Data Staging (T1074.002)
    Required data: XDR Agent with eXtended Threat Hunting (XTH)
    Detector tags: Data Detection & Response
    Attacker's goals: Collect data and stage it on an endpoint in the organization.
    Investigative actions: Check whether the process that created the massive file activity creates network connections as well. Check which files the process performed the activity on. Check whether other users in the organization used the same process for file activity.

    Variations

    A user performed suspiciously large file activities over 1 GB in a short period of time

    Low overridden

    A user generated massive file activity by size or distinct file count. overridden