Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • Abnormal process connection to default Meterpreter port Informational 1 variation

    This process has probably been compromised by Meterpreter and is now used by it to run malicious commands.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    N/A (single event)
    Deduplication:
    1 Hour
    ATT&CK tactics: Command and Control (TA0011)
    ATT&CK techniques: Non-Standard Port (T1571)
    Required data: XDR Agent
    Attacker's goals: Run Metasploits's malicious post-exploitation tool named Meterpreter to further compromise the host.
    Investigative actions: Verify if the destination IP is running a Metasploit server. Look for malicious action being done by the suspicious process.

    Variations

    Abnormal process connection to default Meterpreter port on an internet-facing server

    Low overridden

    This process has probably been compromised by Meterpreter and is now used by it to run malicious commands. overridden